Here's IP data related to requests: https://gist.github.com/panabee/9595411. Can post more if more is needed for diagnosis.
Questions:
1) How do we confirm if the site is under attack?
2) If the site is under attack, how can we ward off the attack and prevent future ones?
3) We seem to have a ton of sleeping MySQL connections that continue to crop up even after we try killing them. Is this symptomatic of a botnet attack?
We appreciate any help or guidance anyone can offer.
Thanks!