It's not so hard to use Tor for that. I wonder how the Tor exit nodes are distributed across the globe and see how that correlates or not.
[bauruine@tp:projects/misc]$ python check_ip_tor.py /tmp/malicious_ips.txt
Got a total of 6303 malicious IPs
Of which 15 are Tor relays
Edit: Small addendum here are the worst 5 ASNs. 1607 TENCENT-NET-AP-CN
738 DIGITALOCEAN-ASN
483 KIXS-AS-KR
205 GOOGLE-CLOUD-PLATFORM
115 OVH