Skutečně to byl útok SQL injection, pocházel nejspíše z Číny.
Z diskuze k článku:
The only reliable protection against SQL-injection is sever-side validation. Check the content and length of input strings before passing along to the database. Anything less is just lazy.
Viz
The 10.000 web sites infection mystery solved.