I still haven't been able to rid myself of the Iranian servers revealed on the NYX connections page.    I don't know their purpose but they slow the relay by about 85%.  I have dropped them in the iptable input chain, restarted the VPS, but they show up after a day or two in spite.  Today there were 121 of them with a large range of IPs.  There have been as many as 1400 in a single day.  None have identifiable hashed fingerprints. 
I've enclosed a couple attachments of my input table (partial) and the NYX connection page (also partial). 
Can anyone enlighten me regarding this situation?  I will probably dump the exit relay if I can't fix this intrusion.  Thanks people!!
-potlatch



Sent with ProtonMail Secure Email.