From personal experience: most activity you're likely to see from Tor exit nodes is fraudulent. Absolute bottom-of-the-barrel cesspool traffic trying to probe for vulnerabilities, commit fraud, scrape content, avoid IP blocks, and generally abuse your site in ways that the attacker wouldn't be comfortable doing with their own IP address. It's really tragic - given the potential of the network as a privacy tool - that it's mostly used for evil, not good.