they are trying to find a vulnerability on your server. I see them every day on my server.
Remember: not indexing an IP address does not improve security: botnets that try to attack users do not care about DNS, but ip. It looks like your home: your street and your address are public, but it is better to keep the doors closed.
What I see every day are bots that do verbal attacks on ssh and general vulnerability checks on ports 80 and 8080.
Very often, bots are iot devices with upnp enabled and the DEFAULT administrator name unchanged. Sometimes this is a raspberry pi (and similar) with default login information.
So, the best countermeasure you can do is change the default for logging in, turn off upnp if you do not need it, and if you can, turn off the login for regular users (e.g. root, admin, pi, ecc )
Adding some characters to your username (e.g. changing pi to user_pi) may help you with dictionary attacks (pre-programmed combinations of username and password), but the best password is the best. Using a localized name will not work: sometimes bots use different dictionaries according to your IP address.
source share