ok and bots back, at the moment I've learned they are itting on existing pages on a couple domains with custom error handlers setup, this makes php, or asp go into a processing loop of sorts making a bombardment of error page processing to cause a major slowdown.
Just as I got a bunch of the requested pages blocked they shift to requesting image. for now, custom 404 handlers for domains being attacked are being disabled.
This battle is getting the best of me at the moment I feel like pulling hair out!
We are already working on some long term solutions to protect against such crazy attacks and botnets, but it is not ready to deploy production systems now.