I run an open source honeypot that collects these botnet scans and produces blocklists.
Blocklist download and configuration: https://knock-knock.net/blocklist
Honeypot dashboard, where you can see attempted attacks in realtime: http://knock-knock.net
This looks cool, where can I find the source?