I have seen them crawl and check any active relays (including relay) they don't have any clear details. We can only tell if we check reverse domain of the IP visiting our relay. Nostr.band has better signature with origin header crawler.nostr.band when they connect. Although, any headers value are note really reliable becausr anyone can also fake it 😅
Discussion
I found them. They're acting very strangely. No wonder they got banned.
I think it is mainly because the frequency of their bot hit the relays quite a lot thus looks like suspicious traffic. If i'm not mistaken they also access relays using various location (Europe, Asia, America) maybe to make sure their reports are correct (online relays reports)
yes
[02/Dec/2023:17:30:11 +0300] "GET / HTTP/1.1" 200 292 "-" "node-fetch/1.0 (+https://github.com/bitinn/node-fetch)"
[02/Dec/2023:17:30:11 +0300] "GET / HTTP/1.1" 101 2 "-" "-"
from six servers in a short amount of time