Report for IP: 31.134.5.197

Threat LevelHIGH61/1002 rule types across 2 attack categories
5 incidents on record · 2 rule types · confirmed on global blocklist · persistent 21-day campaign · seen 8h ago
PTR N/A
Org / ASN OOO Lux
Country 🇷🇺 Russia
City Moscow, Moscow
Timezone Europe/Moscow

Attack Analysis

WordPress XML-RPC Abuse
This IP targeted xmlrpc.php, a legacy WordPress endpoint that has been abused for brute-force authentication attacks, credential stuffing, and DDoS amplification. Any direct access to xmlrpc.php is an attack or reconnaissance attempt; modern WordPress sites should disable it entirely.
Listed on 1 threat-intelligence blocklist
  • This site (WordPress attackers, 90 days) — This site's own data: an IP that attacked WordPress sites and was reported here within the last 90 days. Independent of the third-party lists above.
A single community list matches, so treat this as moderate evidence.

Reports (5)

Date Severity Description
29 Sep 2026 - 16:43 low unwantedip.eagleeye-intelligence.com (WordPress-targeting IPs, 90d)
29 Sep 2026 - 05:56 low unwantedip.eagleeye-intelligence.com (WordPress-targeting IPs, 90d)
28 Sep 2026 - 04:52 low unwantedip.eagleeye-intelligence.com (WordPress-targeting IPs, 90d)
27 Sep 2026 - 15:31 low unwantedip.eagleeye-intelligence.com (WordPress-targeting IPs, 90d)
8 Sep 2026 - 23:06 high WordPress: xmlrpc.php accessed