The port "under attack" is not the SQL Server port, (1433), it's the LDAP port, (Lightweight Directory Access Protocol). It's probably some kind of worm or bot just firing these packets looking for unfirewalled Win2k/XP boxes to see what it can find. Since it's being blocked I would forget about it.