Nice. Real nice.
129.222.136.140, 5/14/23, 2:13:58, GET, /wp-login.php
129.222.136.140, 5/14/23, 2:13:58, GET, /xmlrpc.php
To be fair, I have been seeing a huge uptick in requests for those two files in recent months from first-world (residential) IP's that I wouldn't normally block (and that I still won't block because of the impracticalibility of it).
User-agent in this case was
Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
I am curious though, as to what sort of malware / trojan / botnet is inhabiting the devices behind these IP's. I don't think this is infected modems or routers.