Banning IPs via classic firewall tools (iptables/nftables/etc.) still works great for banning an annoying IP (or even subnet ranges, when they change in the same data center etc.)
A bit cat and mouse, but automations like Ansible exist.
Maybe there should be a DNS based IP blacklist like for SMTP?