i can not stop this is. how can i do that ? try to every secont only one domain on cwp.
you can put unwanted ip on /etc/csf/csf.deny , but not recomended ( i think), because you might will have a huge list.
Easiest way is using real time rbl checking, at least barracuda, spamcop, spamhouse and sorbs