What usually happens in these instances? A warrant for one of those computers at any of those 185,000 IPs needs to be examined, monitored, and then the proxy-snail-turtle-chain needs to be traced, which could be long, onioned (like Tor) and well -- obfuscated with lots of extra superfluous traffic. Are botnets just considered collateral in a highly vulnerable computersphere? When does anything get done, I really have disdain for the kind of people who run botnets. Every single one I've met, years ago, when I was more in the scene was a power-hungry tool out for petty cash through bribery and destruction.