ModSecurity with the latest OWASP CRS ruleset takes care o allot of these.
The Comodo ruleset if now over a year old, and is dead.
Also as @overseer mentioned, Cloudflare's Proxy helps, but only if they hit the domain name.
If they try a DDoS against your IP, then it doesn't help.
Unfortunately dealing with these script kiddies is part of the job anymore.
Then you have all these scanners from the hacker groups constantly hitting stuff.
censys and leakix are really bad if you look at the logs.