Hang any SSHD on the internet, and within minutes you get these attempts. You can choose to log the passwords if you like and this is what you would see.
The "POSSIBLE BREAK-IN ATTEMPT!" message worried me for a bit but a little googling and the fact I've disabled password login calmed me down.
Presumably, changing my sshd port will drastically reduce these attempts right? Or do attackers routinely port scan servers?
Only nuisance is that the higher ports may be blocked, for example my uni blocks my new ssh port so I can't connect to the vps when I'm on campus.
Mind you it isn't that this is a defense, but it gets the drive-by scanning stuff out of the log.
By all means disable password login, and all direct root login.