File: //var/lib/modsecurity/audit/20251208/20251208-1944/20251208-194416-aTdw4LhenDUAADz6XREAAAAR
--8f3e6c0d-A--
[08/Dec/2025:19:44:16 --0500] aTdw4LhenDUAADz6XREAAAAR 4.189.120.86 51100 127.0.1.126 80
--8f3e6c0d-B--
GET /wp-admin/includes/ HTTP/1.1
X-Real-IP: 4.189.120.86
Host: crazyfeetlinks.com
Connection: close
User-Agent: Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36
Referer: https://www.google.fr/
Accept: text/html, application/xhtml+xml, application/xml; q=0.9, image/webp, */*; q=0.8
Accept-Language: en-US, en; q=0.5
Upgrade-Insecure-Requests: 1
DNT: 1
X-Forwarded-For: 201.160.238.217
--8f3e6c0d-F--
HTTP/1.1 401 Authorization Required
WWW-Authenticate: Basic realm="Restricted"
Content-Length: 469
Connection: close
Content-Type: text/html; charset=iso-8859-1
--8f3e6c0d-E--
--8f3e6c0d-H--
Stopwatch: 1765241056571431 591 (- - -)
Stopwatch2: 1765241056571431 591; combined=40, p1=36, p2=0, p3=3, p4=0, p5=1, sr=24, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.1 (http://www.modsecurity.org/); 200911012341.
Server: Apache/2.2.31 (Unix) mod_ssl/2.2.31 OpenSSL/1.0.2k-fips PHP/5.3.29 mod_fastcgi/2.4.6
Engine-Mode: "ENABLED"
--8f3e6c0d-Z--