I have a ddos attack that manifests itself in code in a client's proxy.ssl.log file that looks like this \x00\x00\x00\x00\xA27\xF7\xFF\xD1\x9D.
Somehow I'd like to ban any ip whose address ends up in that log. Too many IPs to block manually in the iptables.
So I'm hoping to get fail2ban...