Ok.
That is embarrassing...
I noticed one of the attackers is an IP address from Microsoft corp in Beverly Hills. I think the ip was : 157.22.39.223.
Merck & Co as originating location for an attack, also passes by often.
I'd expect to see traffic from MS, but Merck?!
None of that is really surprising to me. Corporate systems get compromised, and are used as a pivoting point for attacks all the time. PCs become members of botnets. There's also the possibility that it's someone that works in Info Sec who is "playing" with the honeypot (the legalities of which are definitely a gray area, but could very easily result in jail time).
