Distributed can mean different things, especially if you can spoof addresses, in which case you can do fake distribution (causing src based filtering to be useless). If you know it's just a single bad AS that is doing it, then you can block the AS, but if it's distributed amongst multiple AS'es that's harder. Same with reflective attacks, the source of the traffic might not be the source of the attack and might be a legitimate source which you cannot block because your internet wouldn't work anymore (i.e. when it's DNS servers or NTP servers doing the reflection, or a GCN address which would completely take an ISP's section offline).
It's not as simple as sending a large volumetric load from A to B. It used to be that way a decade ago and it can be effective today, but it's not the only way it's happening.
Most robots participating in this are unwitting. It's incredibly unlikely someone is paying... even with stolen funds.
Often a sort of malware that more or less sits dormant until command/control sends a target to attack
edit: To the individual machine, not a lot. The sum total is where the denial of service comes in - everything has a tipping point.
This is the problem with botnets - all the connections look like real traffic at first glance.