This IP address has been reported a total of
15
times from
7 distinct
sources.
59.12.253.15 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(mod_security) mod_security (id:210740) triggered by 59.12.253.15 (-): 1 in the last 300 secs; Ports ...
show more(mod_security) mod_security (id:210740) triggered by 59.12.253.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 21:49:55.802854 2026] [security2:error] [pid 26085:tid 26085] [client 59.12.253.15:33518] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||panmaneecnc.com:80|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "panmaneecnc.com"] [uri "/"] [unique_id "aff7QzrR1T5xz2ksLqri3AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
(WPLOGIN) WP Login Attack 59.12.253.15 (KR/South Korea/-): 10 in the last 3600 secs; Ports: *; Direc ...
show more(WPLOGIN) WP Login Attack 59.12.253.15 (KR/South Korea/-): 10 in the last 3600 secs; Ports: *; Direction: 1
show less
26 Feb 2026 23:44:04UTC:Distributed Brute Force Password Attack (smtp, ftp, imap, pop, ssh) includin ...
show more26 Feb 2026 23:44:04UTC:Distributed Brute Force Password Attack (smtp, ftp, imap, pop, ssh) including ip address 59.12.253.15
show less