I've never had this before, but it could be more common that I've experienced.

Since Sunday my logwatch email has been reporting a few attempts each day to ssh connect using the users:

test
guest
admin

The originating IPs do not seem related.

Has anyone any experience of this or is this something new. Some kind of worm perhaps?

Steve