148.130.0.0/16
Not everyone responds to a ping but I suspect most do
Also, be careful as "host discovery" can be viewed as a type of "hacking" depending on who you are and who is watching/judging you.
Your second point though... really? Do you have any sources for anyone, anywhere being charged for using ping?
Quite a few years ago the security team of the organisation I worked at didn't have our internal vulnerability scanning services automated. It relied on them capturing the IPv4 addresses (specifically the /32's, not the subnets) and manually entering them into the engine.
Our security team mistyped a handful of these addresses and instead of the scan running across our internal infrastructure, we scanned WalMarts external facing infrastructure in the US from Australia.
These scans were happening semi-regularly for a period of a few weeks before we received a cease and desist and the sec. team realised their error. I'm still rather surprised more didn't come of it.