The Virtualmin default access port is set to 10000. Anyone who knows this can try to access Virtualmin with a guessed password. Hackers will exploit this with bots that try thousands of passwords per second.
You avoid this by simply changing default webmin-virtualmin password to an uncommon one. This video shows how to change default Virtualmin access port in Webmin.
You can read more details here.
https://vpsfix.com/5775/change-virtua...