Last night between 5:46:48AM and 5:50:02AM, the IP 209.50.238.122 attempted to SSH to the admin account of one of my boxes 318 times. At 5:50, DenyHosts noticed and shut the IP down.
Though the IP is doubtless a spoof, it’s amusing what happens if you hand it to hosts
:
$ host 209.50.238.122
122.238.50.209.in-addr.arpa domain name pointer mail.harvard.com.