Increased TOR exit nodes in block list?

Anyone else seeing an increase in TOR related traffic on their firewalls? I have 27 blocked TOR relays or other exits nodes this morning. The ET rules block TOR traffic and I assume this is an attempt to disguise an attack against an open port. Most of these nodes are repeat offenders.

Looking deeper most of these are also carrying RDP against non-standard ports, so someone is trying to get in.