For wp-login bots I serve them a nice chunk of random (generated by a fuzzer) html in the hopes that 1. It wastes abit of their bandwidth/memory and 2. it crashes their parser
In reality I guess bots nowadays are sturdy enough to not get stuck or crash but who knows, feels good to do something :-)
Tarpit instructions https://nyman.re/super-simple-ssh-tarpit/
Wp-login page https://twitter.com/gnyman/status/1181652421841436672?s=20
And I remembered another nice trick which someone else came up with, zip bomb the bots :-)
https://blog.haschek.at/2017/how-to-defend-your-website-with...