The attack has changed in my case for sure. It was attacking relentlessly hitting multiple users from the same ip in waves. One big wave, and minutes later, another wave. I had previously had some strange attacks back at the first of the year and consequently installed honeypot and stopspammer. So when the most recent attacks of login attempts the only thing i changed was upgrading from rc3 to rc5, which didn't seem to make a difference. But after banning several of the ip addresses(by ranges as it was not anything close to current member ips) and being now about a week after the main relentless attack, I'm seeing a completely different pattern -
Now, you see one user login attempt every few minutes, but the next attack will be from a different ip and attempting login using a different name. It does seem to be cycling only about 5-6 usernames, but again, every time it tries(spaced out time frames) it is from a completely different ip, and the ip may be from arin one time, then from ripe network the next. After an hour or so, you might see an ip address used the last hour now attempting a different name than before, but again still pulling from what seems to be a very short list of about 5-6 or so names.
I am still receiving some attacks from the original group of ip address seen in the first wave which have been banned(up to 100 or so attempts getting the 'sorry u are banned' msg) but nothing compared to the close to the several hundred attempts per day i was receiving before)
Hope this info helps in the fight to find an answer,
Maver!ck