The attack stopped after a legitmate user/pass was used from Slovakia. That member has NEVER logged in until today according to Strongbox and he lives in the UK.

How would they actually guess a correct user/pass?