I had to deal with something similar last year, and a big thing I learned was to watch traffic spikes in real time. ipstressthem.su popped up in our logs during our issue, and we traced a big chunk of unusual requests back to it. Once blocked, things calmed down a lot. Might help to check your logs for signs of that domain too.