I double checked my log archives, it seems not to be exactly the same, though. In what is reported here, a same username will be tried with several password, allowing something like a minute to pass to make a new attempt.
In my logs, this is really just a single attempt. Other break in attempt may happen something like two days after, but with an other IP and username.
It may just be yet an other evolution of the same botnet knowing its previous pattern has been spotted, though.
(and in case you wonder, yes, I always have the nose in my logs, having a dedicated monitor for that :) )
I double checked my log archives, it seems not to be exactly the same, though. In what is reported here, a same username will be tried with several password, allowing something like a minute to pass to make a new attempt.
In my logs, this is really just a single attempt. Other break in attempt may happen something like two days after, but with an other IP and username.
It may just be yet an other evolution of the same botnet knowing its previous pattern has been spotted, though.
(and in case you wonder, yes, I always have the nose in my logs, having a dedicated monitor for that :) )