I've been watching this specific botnet since April, almost 6k attempts/server so far.. it's slow and wide (rarely repeat IPs, max rate was 2/minute, but it's more like 8-20/day now) so most detection approaches won't work (search your logs of sshd for "Received disconnect from", "Did not receive identification string from" and "Connection closed by"). It's also everywhere.. a lot of digital ocean, but also AWS, google, Azure. Government IPs, consumer IPs, IPs reported as part of backbones
[0]: https://news.ycombinator.com/item?id=24217592