I run a small niche photography site which has posting capability and I look at the logs quite a lot. There are all sorts of ways to stop the post bots like UA, country, IP but I've abandoned them all because the processing overhead outweighs the benefit - they never succeed in actually posting anything.
These bots all behave the same way, they come to a page [get] and then try and post to exactly the same page [post]. Most come from China but Ukraine, Russia, US, South Africa, France, Netherlands have a few too.
The other bots try and expoit loopholes like looking for wp-login, admin etc. Again they never find anything and rather than giving them any attention I just to let them 404.
I'd love to understand a bit more about them, especially those former China get/post things, because they seem so utterly pointless. They never succeed. How are these things run, and why do they identify themselves so easily (MSIE 6). What are they, link spam bots, or infected computers? Or just some script being run going down thousands of addresses?
Many thanks