One of my Linux servers was port scanned last night a dozen times in just a few seconds, in-between 23:00 and 00:00 GMT. The IPs originated from different parts of the world. I noticed how a single host would try to port scan a few times, then another host would try. But there would never be more than 1 host port scanning at the same time. Does this sound like the behaviour of a virus/trojan or more like someone controlling a botnet?