This also matches the logs of all the servers that I manage. lastb returns virtually nothing for servers where I moved SSH to a non-standard ports, but tons of attempts for those which I haven't - once that port responds, malwares try to log in using a list of pre-defined usernames: root, tom, tomcat, etc... Some of these servers were nearly DoS'ed by these login attempts in the past (as eventually OpenSSH would say "that's enough" and stop answering connections, which triggered my Nagios monitoring on these servers were SSH stopped responding).
All issues that are resolved by moving SSH to a non-standard port.
Check "lastb"'s output sometime to see what I mean.
All issues that are resolved by moving SSH to a non-standard port.
Check "lastb"'s output sometime to see what I mean.