DC = Data center. These are IP ranges that are in use by data centres, cloud providers, etc. Ie, Digital Ocean, OVH, Hertzner, HostPapa, to name a few.
Our ISP already blocks huge DDOS style attacks, we don't need CF for this.
Cert renewal is not an issue, we already have a robust free solution.
Caching doesn't much help us as the pages SMF serve are generally non-cachable (it's from a pre-caching era, dynamic content on every page load)
We had successfully filtered everything we needed to until a few weeks ago when these proxy attacks started. The traffic comes from people that have installed free games/apps on their phones or browser extensions that allow their PC to become part of a proxy bot net. The bots then proxy it via their device, a single request every few days, but there are enough installations out there that it causes a flood of incoming requests that can't be identified from real users. It's not a per-ip flood, there is no pattern to search for, and the requests are coming from regular user's networks (DSL/Cellular, etc).