How to stop WordPress ddos bot attack in shared cpanel server?

If you have hosted lots of WordPress website in your shared hosting then you may have came across this situation where attacker tries to brute force attack on wp-login.php increasing server load hence doing Ddos attack. You can’t even apply modsec rules or csf rules as attacker uses one ip no more than two times. […]