Noticed that my server was down today and had an existing DNS issue from before. I checked my log and saw ip ' 217.218.253.14 ' had got in VIA FTP even though i had FTP turned off. anyway I did a ip geo locator and saw that it came from IRAN.. so heads up to block that ip!
oh how he gets in? Try installing some firewall, It will help in getting ban any IP easily. also do security audit of your server in order to reach to the cause of the attack. I would suggest to hire some 3rd party server management company to do it for you.
have some brute force protection sort of thing. helps saving your server from dos and stuff like this.