Most of them are probably bots running without the knowledge of the IP owner. There’s little benefit to sharing those IPs with anyone other than the provider who owns them.
It feels to me like we're too polite, so we're letting the infected walk amongst us. It might not be their fault, but I'd be guessing it'd also be better for victim to find out sooner rather than later if they're pwned.
I suppose the slippery slope / end game of this would then concentrate all intentional malicious traffic to VPNs and proxy's and Tor and the like, with them becoming useless due to being blocked.
I block any IP address that's probed any of my ports they have no business probing. See https://news.ycombinator.com/item?id=39171782