Sometimes bots just go through the ipv4 space and find your host. In addition to what was already suggested. I also recommend to use Authenticated-Origin-Pulls (but only if you expect all http traffic to come from Cloudflare) https://support.cloudflare.com/hc/en-us/articles/204899617-Authenticated-Origin-Pulls. Actually never mind, you probably don’t have access to the necessary configuration files if you are on a shared hosting provider.
I read it as Access Rifle, I guess it can also be used to defend against bots…
I think I fix it and I am not sure it was the bot attack. Anyways I did challenge traffic from some countries: Cambodia, China, Russia, Ukraine etc for all my accounts. That seems to work and it is easy to do it.
However in my WHM I noticed that apache_php_fpm service was the one that using most of memory so I went and downgrade those domain names from php 7.2 to 7.1 …
I also noticed that some domain names google console plugin was disconnected or a domain name was http on google webmaster and I had it https on my server and it was getting redirect it when try to crawl …
I have almost a day a very good performance for my server.
I am not sure what did the job … but I am happy now :)))
Thanks to all of view that try to help me