interesting! thanks for sharing!
DaeConn seems to be a crawler with the connector UA and the hard coded IP is just testing the crawler works.
maybe the other paper (or some other research) might have this python-bitcoinlib UA and address rate limiting? though the timeline feels a bit short - it was presented in June and the addr spam started in April/May.