A simple test of blocking those IPs would answer your question in whether or not it is an attack. 10 or 20 doesn't sound like enough for a full-fledged DDOS but of course it all depends on the server resources. If nothing breaks and you get no complaints after null-routing those IPs - they were malicious bots. An alternative would be to use Web Application Firewall such as MojoShield or Cloudflare. The solution is made specifically for weeding out potential attacks and stopping malicious bots.
__________________
MojoHost.COM | natalie at mojohost dot com | Skype natalie.ac | Telegram @znatalie. Since 1999: 70 Adult Industry awards for Best Hosting Company and professional excellence.
|