Hi Gareth,
It does appear as though your server or hosting provider had been compromised.
A server I host received unsolicited traffic from 92.204.218.140 trying to access wp-login.php (WordPress login page). My server is brand new and not advertised on the internet, so it looks like your server is performing some form of scanning. You may want to inspect your server or contact your hosting provider to have this repaired. Hopefully the malicious process is limited to scanning, but it could do a lot worse.
Here's the log entry from my server, of that helps:
92.204.218.140 - - [20/Feb/2022:11:05:10 +0000] "GET /wp-login.php HTTP/1.1" 404