Slight bump. There's a simpler way to confuse bots, just add empty admincp and modcp dirs, then copy a .htaccess file to both that contains a single line:
Alternatively you could provide access to this (empty) dir with .htpasswd and an extremely long and completely random username and password, which they're of course quite welcome to try to bruteforce

All of this assuming you've moved your *real* admincp and modcp dirs of course.
