ngrok probably issued you a certificate for the subdomain, which goes into Certificate Transparency (CT) Logs, which are public. There are a fair number of bots that listen to CT Logs, and then instantly probe the site, as you can see. On Pro or above Cloudflare also has Web Application Firewall Rulesets like OWASP ModSecurity Core that can catch and block some of these (assuming the subdomain is proxied). Nothing to worry about too much though, just make sure your software/server is all updated, and that you’re not exposing anything private through it.