Yes. But PaulyC was not running a big account with a well-known and hallmarked IP, right?
As I understand, this applies to all machines, not only big, hallmarked nodes, right?
And since exploits usually depend on a particular environment, they might not work in all cases.
So some bot scans the network and tries this exploit on every machine it can find.
In some particular combination of OS/soft it works. Boom, money stolen.