You should also try implement recaptcha on your comment forms on your Wordpress blog. The recaptcha can be placed anywhere that has a form and that should help you thwart those spam as tools nowadays are unable to solve recaptcha - unless if it is a paid service and that will burn the spammer's budget in the process. Recaptcha on your Wordpress login form also helps thwart those brute force attack, as if the captcha is not solved, even if the brute form guessed the right password, but the wrong recaptcha, they still do not get access.