In online.php you will see bots trying to login randomly to accounts they think exist. It's usually not a brute force attack on real accounts. Unless you have actually seen what account they are trying to log into by checking the server logs? vBulletin itself has no way to identify what account they are trying to access.
Putting a captcha on login will unnecessarily annoy your human users, in my opinion, and really won't stop any bots that are from the XRumer program for example, since that one and a few others defeated captcha long ago..
BUT, I do suggest a good and reliable coder for you, and suggest contacting him via private message:
https://vborg.vbsupport.ru/member.php?u=330766