I have had to fight off several, one of which I recorded over 1 million unique IPs, all random and coming out of nearly every Vietnam and Indonesian subnet, mostly residential. My site normally gets 5-10 requests per second and was now getting over 1000+ for 12-14 hours per day for 3 weeks straight. It always started at the same time of day, almost like it was on a timer. Luckily, that one all used a User Agent with the same old version of Chrome in the string and was easily blocked. But the attack continued even though every request was reporting 403 Forbidden back to them. So its like they weren't even paying attention to the data they were getting.
The next one was out of the same region but they randomized the User Agent, but still in a way that wasn't too difficult to filter out. Once they figured out to better replicate a real User Agent, then I had to resort to blocking the entire countries at the router.
Other attacks have been random IPs from all over the world, a mix of residential and cloud providers. Since then I have installed Anibus, and I haven't had a single issue.