For months our site registered non-destructive bot activity: low-level probes coming mostly from automation clusters located in Ireland. Nothing spectacular, just silent persistence.
Early in the day the behavior changed noticeably and we detected what was clearly an operation directed by a real attacker.
Reconnaissance phase: at 7:25 AM UTC-5 our geoEvents system registered a visit to the site root coming from Los Angeles. Unlike previous accesses, this request had a human behavior fingerprint: profiled user agent, clean browser headers, normal screen resolution, and coherent interaction times. In other words, a planned probe.
Attack trigger: at 8:14:35 AM a request was made to the decoy endpoint analytics6x4Z72xq1.html, a bait file created precisely for this type of testing. Less than a minute later Cloudflare logs showed that the attacker had bypassed the CDN cache and hit the origin directly, a mistake on their part.
By hitting the origin they activated our custom logger firestoreMirror.js which captured IP, timestamp, user agent, referrer, and tagged the event as CDN bypass in addition to adding geolocation. The entire trail was archived as a complete signature.
Technology stack used in the trap: Firebase Firestore configured as a mirror for real-time tracking, Cloudflare DNS and CDN logs, pseudolegitimate decoy endpoints, geolocation and screen fingerprinting, and custom honeynet logic for collection and correlation.
Lessons learned: CDN shielding is not always enough; botnets are often smoke that attackers use as fog to hide targeted actions; Firebase is a powerful tool beyond app data storage; and when you build public systems that expose malicious behaviors, those systems will be tested.
At Q2BSTUDIO, a company specialized in custom software and application development, we work integrating artificial intelligence, cybersecurity solutions, and AWS and Azure cloud services to protect infrastructures and extract actionable intelligence. We offer custom software services, custom applications, business intelligence services, AI for enterprises, AI agents, and Power BI deployments for advanced visualization and reporting.
If your team designs honeypots, threat traps, or privacy-first analytics solutions with open tools like Firebase, share your experience. At Q2BSTUDIO we exchange notes, collaborate on hardening, and design secure architectures that combine AI, cybersecurity, and cloud.
Snapshot of the Cloudflare event log: captured on August 7, 2025 at 13:14:25 UTC, the firewall logged a managed_challenge action detecting and challenging the request. Origin firewallManaged. Client ASN CDN77. Country United States. IP address 2a02:6ea0:c803:3091::12. User Agent curl/8.5.0. Requested path /analytics6x4Z72xq1.html. Rule ID 874a3e315c344b1281ad4f00046aab6f. This event matches the hit on the decoy file that validated the origin bypass attempt and was archived as part of the honeynet's internal records.
For inquiries about custom software development, applied artificial intelligence, infrastructure protection, and AWS and Azure cloud services contact Q2BSTUDIO. We are specialists in custom applications, custom software, artificial intelligence, cybersecurity, business intelligence services, AI for enterprises, AI agents, and Power BI ready to boost your project.


