@stefan
Not figured out, but saw this starting about two weeks ago on my (actually pretty insignificant) websites.
The attack patterns were requests to a page they obviously assumed would trigger an elaborate database query, plus an astonishing amount of request timeouts for arbitrary pages, to keep my server busy.
Stopped that via a combo of rewrites, fail2ban and Anubis. Still, the page with the presumed database query gets hammered, but a rewrite instantly takes care of that. The corresponding fail2ban "jail" has a little over 50K banned IPs at the moment, though.
Anyway, its not creating any significant server load anymore. I wonder why anybody would waste so many resources in return for nothing, but well…