Obscure port does nothing.. it eventually finds it and then you'll see tons of servers try that port (unless you constantly move it).
I'm not sure how you imagine Pluggable Authentication Modules would help? Fail2Ban or some sort of active IPS helps, but because the IPs are very varied (and presumably ever increasing) and infrequently re-attempt it doesn't help much.
Note anyone running exposed SSH without keys or certs, should run the detection script[0] (which is just shell and you should read first before installing) provided by Guardicore
[0]: https://github.com/guardicore/labs_campaigns/tree/master/Fri...