My first thought was that someone is spoofing the referrer. I don't know much about crypto exchanges, but it seems like Binance is a pretty "legit" one, which is what made me think they're not sending this traffic (plus, who would do this and leave their actual referrer exposed?). I thought maybe it's a homoglyph phishing attempt, but it seems to just be the legit binance domain string.
I'm curious why anyone would choose to spoof this domain specifically? Most of these bots report no referrer, a few report google or bing. What may be the motivation for using the binance domain?