Looking through the Administrative logs is a real eye-opener. Open today's log with no search criteria, download the file, then pop it into your favorite text editor, sorting on the 14th character (the IP number, most of the time). If you remove the extra lines at the top and bottom then scroll through the file from the top down, you'll frequently see loooooooong swaths of log-in attempts throughout the day from the same IP numbers. On my system they typically try to do a POP login with these 16 common user addresses:
admin, billing, contact, customer, finance, hr, news, noreply, no-reply, postfix, sales, service, shop, support, test, webmaster.
For instance (all China):
04:16:41.055 [106.53.161.136] POP Attempting to login user: admin@aaaa.org
04:21:14.870 [106.53.161.136] POP Attempting to login user: admin@bbbb.org
04:23:36.921 [106.53.161.136] POP Attempting to login user: admin@cccc.net
04:26:04.121 [106.53.161.136] POP Attempting to login user: admin@dddd.com
04:30:10.068 [106.53.161.136] POP Attempting to login user: admin@eeee.com
04:36:45.891 [106.53.161.136] POP Attempting to login user: admin@fffff.com
04:39:27.924 [106.53.161.136] POP Attempting to login user: admin@gggg.org
...
11:38:57.044 [106.53.161.136] POP Attempting to login user: webmaster@aaaa.org
11:43:15.911 [106.53.161.136] POP Attempting to login user: webmaster@bbbb.org
11:45:34.070 [106.53.161.136] POP Attempting to login user: webmaster@cccc.net
11:47:54.212 [106.53.161.136] POP Attempting to login user: webmaster@dddd.com
11:51:48.859 [106.53.161.136] POP Attempting to login user: webmaster@eeee.com
11:57:58.092 [106.53.161.136] POP Attempting to login user: webmaster@ffff.com
12:00:35.041 [106.53.161.136] POP Attempting to login user: webmaster@gggg.org
Total of 210 failed attempts, just from this one IP. You can average these fails around, say, twelve users x six domains per IP, often trying three times a day on each. Most of the time, it's more.
So far I've found these IPs (below) exhibiting that behavior (only about 5% through the file so far), likely all from China. I already have them on the blocked country list, but these IPs appear to not be included in that:
1.212.225.99
1.234.70.54
101.47.73.6
102.130.121.204
102.210.148.98
102.218.10.150
102.53.15.17
102.53.15.18
102.53.15.56
103.106.104.187
103.121.199.166
103.154.231.122
103.244.206.6
103.74.54.116
103.81.87.161
104.207.65.226
106.14.31.49
106.51.67.60
110.93.25.38
112.213.125.12
116.118.47.174 (300+ attempts in 12 hours)
118.219.255.169 (150+ attempts in 12 hours)
125.212.235.151
134.119.183.213
Each of these IPs had more then one hundred failed attempts over the course of the first half of today (midnight to noon). This is only a fraction of the total list.
I would love to have some automated intelligence looking at these trends and permanently blocking an IP number if it fails more then 50 times hitting multiple domains in a day. Seems obvious. But, how?
BTW, I am continually amazed at how many failed attempts come from China. And... why so many attempts at a user named "e9ginpfa-1klghsfw" from so many IPs? Any IP trying to log in with that user name should automatically be barred for life.