Maybe see if your upstream provider can block them or somehow filter them ?
Make a honeypot, or redirect all of that traffivcer over to the FBI servers so they can look at it ? hehehehe
Curious what firewall are you using ? when you say custom coding, as in you got SM to export to the firewall or the firewall to import the list ?
I was looking at PFSense to do something similar as we have a few standard attackers that are sucking down a lot of server resources. I look at our smarter mail logs and i see something like 60% of the activity is saying "blocked" or "banned" or"rejected" for various reasons. i want to eliminate our server having to deal with that and offload it to the firewall.
www.HawaiianHope.org - Providing technology services to non profit organizations, low income families, homeless shelters, clean and sober houses and prisoner reentry programs. Since 2015, We have refurbished over 11,000 Computers !