I noticed these weird brute force attempts on my forum coming from what I presume is a bot, where they try to login with a user that doesn't even exist. Like, they're not even trying the admin account or anything, it's all invalid users. They seem to always try twice too.
I'm not all that concerned at this point but more curious. What kind of attack is this exactly and what is their end goal? It's not like they're actually trying to brute force into an admin account or even any account, considering they're picking usernames that don't exist. It would be rather trivial for them to try to brute force a valid account by simply looking at user names on the forum. What's interesting is they seem to be trying the same invalid user multiple times over multiple days, but at a rather slow rate. Even if they had a valid user they would never get in at this rate. Is this some totally different form of attack I'm maybe not accounting for? Maybe some of those email domains are malicious sites and they hope I go to them to see what it is?

I'm not all that concerned at this point but more curious. What kind of attack is this exactly and what is their end goal? It's not like they're actually trying to brute force into an admin account or even any account, considering they're picking usernames that don't exist. It would be rather trivial for them to try to brute force a valid account by simply looking at user names on the forum. What's interesting is they seem to be trying the same invalid user multiple times over multiple days, but at a rather slow rate. Even if they had a valid user they would never get in at this rate. Is this some totally different form of attack I'm maybe not accounting for? Maybe some of those email domains are malicious sites and they hope I go to them to see what it is?
