Regarding the residental botnets: check their TLS fingerprint, they usually (at least from my experience) have the same few JA4 hashes that don‘t match with modern browsers
Not sure, I couldn‘t find those fingerprints anywhere and I couldn‘t replicate them in any browser I had access to (Safari iOS, Windows & Linux Firefox & Chromium), so I decided to block them. I haven‘t had a single person complain yet. Their UA are usually the most random ones you can find (who uses a PPC mac nowadays?)