Thanks, I have a working script that automatically scans for these connections, adds the IP to a log file and bans them for a day now.
Why bother with it and not ban them for a longer period at once? I don't understand your approach here. I've used 1 month to check whether it is going to stop in the meantime, if it doesn't then these nodes will go to my yearly ban list.