Maybe this is old news but I found it fascinating. One of my firewall rules grabs hack attempts on my routers and throws them into an address list for a week. At that point all traffic from that IP is dropped. Over the years the number of IP's in this list has grown and grown to the point that I currently have over 117,000 entries listed from the last week alone. I decided to investigate a few random IP's to see where they were coming from and what they were. Out of the handful I looked at several of them had port 80 open and turned out to be DVRs called PCBOX which I found alarming. So it made me wonder, are the vast majority of these attempts coming from the same model device or does every compromised computer just happen to have one of these things? Obviously I am not going to look at 100k IP's, but if the first few came from the same type of device it must be pretty wide spread.
Best I can tell, these are the guys attacking me.
http://www.pcboxargentina.com.ar/productos/?id=82
Just thought I'd share. If you're using a DVR secure that thing!