The GFW doesn't really have filtering devices with IP addresses.
For filtering in literal sense, i.e. address based packet null routing, all you can find is general carrier routers with their routing tables being dynamically manipulated by BGP commands sent by the GFW. You can't know where the commands come from.
For "filtering" described in this research, it's active connection disruption with spoofed tcp reset packets. The GFW mirrors traffic via some routers for detection and sends spoofed traffic for disruption. It doesn't have an IP address per se. This tool can find out from which router the GFW mirrors traffic, but not the GFW itself.
Here is a previous illustration on the topology of GFW networks: https://media.torproject.org/image/community-images/topology...