Web logs 404 analysis - all time
Jan 31, 2026
Automatically updated daily

Checking for 404 errors in your logs can reveal more than just broken links, it can also expose files and URLs that attackers are actively scanning for. To track this behavior, we set up hundreds of honeypots and analyzed live web traffic data, giving us insight into which files and URLs are being targeted across the internet.


The table bellow list the top URLs being scanned all time and is updated daily. Most of the data contain WordPress specific URLs, certain plugins and config files that attackers can use.


Rank Scanned URL Counter
#1 /wp-login.php612,417
#2 /autodiscover/autodiscover.xml287,467
#3 /xmlrpc.php143,332
#4 /index.php106,180
#5 /.env102,770
#6 /.well-known/traffic-advice99,866
#7 /sitemap.xml85,180
#8 /api/v2/auth65,359
#9 /201257,492
#10 /40447,767
#11 /wp-json/oembed/1.0/embed46,672
#12 /.git/config42,770
#13 /module/ngmercadolivre/notificacao36,528
#14 /info.php35,539
#15 /manager/html32,846
#16 /file.php32,757
#17 /admin.php32,293
#18 /login30,464
#19 /about.php28,165
#20 /chosen.php27,053
#21 /en/AutoDiscover/autodiscover.xml25,966
#22 /wp-cron.php25,429
#23 /wordpress23,979
#24 /backup22,792
#25 /wp-content/plugins/hellopress/wp_filemanager.php22,670
#26 /wp-admin21,760
#27 /wp20,801
#28 /api/catalog_system/pub/products/search19,130
#29 /alfa.php18,699
#30 /classwithtostring.php18,230
#31 /old18,123
#32 /.well-known/passkey-endpoints17,918
#33 /wp-content/plugins/fix/up.php17,698
#34 /.well-known/nodeinfo17,640
#35 /ioxi-o.php17,598
#36 /wp.php17,371
#37 /_profiler/phpinfo17,364
#38 /aa.php17,260
#39 /goods.php17,064
#40 /1.php16,950
#41 /admin16,848
#42 /404testpage4525d2fdc16,786
#43 /wp-includes/wlwmanifest.xml16,742
#44 /autoload_classmap.php16,739
#45 /en/autodiscover/autodiscover.xml16,601
#46 /atomlib.php16,545
#47 /phpinfo16,357
#48 /bk16,276
#49 /api/v2/marketplace/sellers/376/products/status-batch16,186
#50 /new16,166
#51 /api/v2/marketplace/sellers/376/products/stock-batch16,088
#52 /api/v2/marketplace/sellers/376/products/price-batch16,073
#53 /bc16,072
#54 /.well-known/acme-challenge/about.php15,786
#55 /api/.env15,752
#56 /main15,213
#57 /rest/V1/store/storeViews15,033
#58 /flower.php14,831
#59 /edit.php14,753
#60 /simple.php14,732
#61 /test.php14,726
#62 /file2.php14,562
#63 /lock360.php14,310
#64 /-/-/-/-/-/-/-/-/-/-14,240
#65 /web/wp-includes/wlwmanifest.xml14,147
#66 /admin/config.php14,058
#67 /wordpress/wp-includes/wlwmanifest.xml14,010
#68 /api/v2/categories/6513,887
#69 /shop13,878
#70 /wp/wp-includes/wlwmanifest.xml13,783
#71 /backend/.env13,446
#72 /blog/wp-includes/wlwmanifest.xml13,351
#73 /app_dev.php/_profiler/phpinfo13,309
#74 /2019/wp-includes/wlwmanifest.xml13,208
#75 /app13,201
#76 /admin/.env13,176
#77 /cong.php13,143
#78 /shop/wp-includes/wlwmanifest.xml13,119
#79 /[object%20Object]13,063
#80 /cdn-cgi/rum12,861
#81 /debug/default/view12,833
#82 /buy.php12,765
#83 /makeasmtp.php12,756
#84 /web_api/auth12,733
#85 /.env.example12,479
#86 /AutoDiscover/autodiscover.xml12,466
#87 /website/wp-includes/wlwmanifest.xml12,428
#88 /abcd.php12,387
#89 /pagamento/mercadopago/ipn.php12,322
#90 /news/wp-includes/wlwmanifest.xml12,262
#91 /v2/_catalog12,190
#92 /test12,121
#93 /feed12,121
#94 /contrato/wap/crons/enviar-email.php12,089
#95 /saiga.php12,073
#96 /server-status11,996
#97 /style.php11,958
#98 /api11,614
#99 /radio.php11,541
#100 /asasx.php11,473
#101 /akc.php11,466
#102 /akcc.php11,460
#103 /inputs.php11,448
#104 /.well-known/apple-app-site-association11,365
#105 /telescope/requests11,247
#106 /autoload_classmap/function.php11,096
#107 /acessorios-cameras10,809
#108 /dropdown.php10,708
#109 /wp-admin/css10,522
#110 /k.php10,488
#111 /wp-plain.php10,470
#112 /adminfuns.php10,358
#113 /css.php10,274
#114 /api/v2/categories/6410,248
#115 /api/graphql10,116
#116 /phpinfo.php10,024
#117 /as.php10,005
#118 /home9,962
#119 /login.action9,960
#120 /user/login9,744
#121 /about9,727
#122 /w.php9,638
#123 /api/sessions9,577
#124 /bless.php9,471
#125 /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application9,452
#126 /server9,181
#127 /404.php9,172
#128 /@vite/env9,141
#129 /_all_dbs9,131
#130 /actuator/env9,094
#131 /api/v2/customers/login9,058
#132 /goat.php9,049
#133 /loja/login_layout.php8,889
#134 /HNAP18,766
#135 /cgi-bin/luci/;stok=/locale8,702
#136 /wp-json/sfwd-assignment/18,681
#137 /gecko.php8,658
#138 /files8,613
#139 /wordpress/wp-admin/setup-config.php8,594
#140 /lv.php8,552
#141 /loja/catalogo.php8,453
#142 /php.php8,437
#143 /bolt.php8,401
#144 /config.php8,300
#145 /administrator8,272
#146 /themes.php8,227
#147 /wp-content/index.php8,156
#148 /manager.php8,155
#149 /wp-admin/classwithtostring.php8,103
#150 /.well-known/acme-challenge/cloud.php8,054
#151 /07550e188,052
#152 /nc4.php8,050
#153 /wp-sitemap.xml8,045
#154 /403.php8,035
#155 /appWP/lab/wp-admin/css/colors/blue/blue.php7,970
#156 /wp-content/plugins/woocommerce/includes/gateways/locks.php7,910
#157 /wp-admin/images/moon.php7,876
#158 /wp-content/wp-conflg.php7,783
#159 /index/function.php7,747
#160 /contato7,727
#161 /wp-admin/setup-config.php7,725
#162 /wsa.php7,710
#163 /f35.php7,501
#164 /wp-content/themes/seotheme/db.php7,495
#165 /wiki7,493
#166 /images/images/cache.php7,481
#167 /g/collect7,442
#168 /gmo.php7,427
#169 /gg.php7,422
#170 /admin/index.php7,418
#171 /mar.php7,372
#172 /pb7,370
#173 /content.php7,357
#174 /doc.php7,342
#175 /tinyfilemanager.php7,323
#176 /users.php7,250
#177 /new.php7,243
#178 /upload/banner7,226
#179 /zwso.php7,189
#180 /blog7,155
#181 /filemanager.php7,108
#182 /mm.php7,106
#183 /api/v3/community7,103
#184 /shell.php7,092
#185 /wp-content/admin.php7,081
#186 /wp-admin/index.php7,071
#187 /wp-content/themes/admin.php7,045
#188 /s/1313e2236313e20373e2538313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties7,037
#189 /images7,003
#190 /moon.php6,954
#191 /wp-content/autoload_classmap.php6,944
#192 /2018/wp-includes/wlwmanifest.xml6,913
#193 /null6,912
#194 /system_log.php6,877
#195 /class.php6,867
#196 /cms6,826
#197 /wp-admin/css/colors/blue/index.php6,786
#198 /wp-admin/js/index.php6,742
#199 /.env.bak6,731
#200 /wp-content/themes/about.php6,723
#201 /cc.php6,701
#202 /install.php6,609
#203 /boaform/admin/formLogin6,604
#204 /api/v2/products/stock-batch6,594
#205 /wp-content/video6,575
#206 /feed/mnpodcast6,574
#207 /wp-admin/wp-conflg.php6,557
#208 /.aws/credentials6,490
#209 /mah.php6,479
#210 /wp-api.php6,455
#211 /2020/wp-includes/wlwmanifest.xml6,438
#212 /wp-admin/js/autoload_classmap.php6,426
#213 /api/v2/freights/3166,393
#214 /g.php6,376
#215 /222.php6,355
#216 /wso.php6,325
#217 /wp-setup.php6,289
#218 /wp-includes/fonts/admin.php6,257
#219 /mini.php6,239
#220 /php_info.php6,209
#221 /app/.env6,206
#222 /rest/V1/inventory/source-items6,203
#223 /wp-json/mod/v1/check-site6,198
#224 /api/shared/config/config.env6,163
#225 /laravel/.env6,148
#226 /.well-known/acme-challenge/xmrlpc.php6,099
#227 /file17.php6,072
#228 /xmrlpc.php6,053
#229 /uploads6,035
#230 /ahax.php6,029
#231 /loja/busca.php6,005
#232 /wp-content/about.php5,997
#233 /file5.php5,973
#234 /.env.local5,971
#235 /admin/controller/extension/extension5,963
#236 /sdk5,953
#237 /admin/function.php5,922
#238 /contact5,914
#239 /evox/about5,880
#240 /wp-admin/maint/about.php5,855
#241 /foq.php5,827
#242 /core/.env5,784
#243 /assets/images/accesson.php5,782
#244 /Form5,778
#245 /sitemap_index.xml5,764
#246 /default.php5,753
#247 /wp-good.php5,693
#248 /wp-includes/fonts/index.php5,685
#249 /wp-content/style.php5,646
#250 /wp-content5,631
#251 /wp-editor.php5,594
#252 /wp-includes/IXR/autoload_classmap.php5,585
#253 /13.php5,475
#254 /wp-json/sfwd-lessons/15,437
#255 /undefined5,405
#256 /loja/cartService.php5,390
#257 /item.php5,373
#258 /about/function.php5,356
#259 /a.php5,344
#260 /byp.php5,321
#261 /wp-json/sfwd-topic/15,302
#262 /wp-admin/edit-tags.php5,257
#263 /files.php5,229
#264 /sk_es/vozik5,216
#265 /wp-content/plugins/WordPressCore/include.php5,210
#266 /function/function.php5,201
#267 /wp-content/plugins/wpterm.php5,198
#268 /comment.php5,183
#269 /pinfo.php5,170
#270 /wp-admin/admin-ajax.php5,165
#271 /.env.prod5,140
#272 /s.php5,134
#273 /.git/HEAD5,124
#274 /password.php5,116
#275 /wp-trackback.php5,050
#276 /api/v2/products/16593714625,030
#277 /apps/.env5,018
#278 /api/v2/products/16593701435,017
#279 /api/v2/products/16593720225,015
#280 /api/v2/products/16593695925,005
#281 /.git/index5,000
#282 /api/v2/products/16593690384,996
#283 /api/v2/products/16593711944,993
#284 /api/v2/products/16593706904,988
#285 /api/v2/products/16593703154,977
#286 /api/v2/products/16593706494,974
#287 /api/v2/products/16593705404,973
#288 /api/v2/products/16593693184,973
#289 /m.php4,966
#290 /api/v2/products/16593694854,966
#291 /api/v2/products/16593710294,964
#292 /api/v2/products/16593718844,963
#293 /api/v2/products/16593699414,953
#294 /api/v2/products/16593705394,949
#295 /api/v2/products/16593697654,948
#296 /api/v2/products/16593719504,945
#297 /api/v2/products/16593712174,945
#298 /api/v2/products/16593714894,940
#299 /api/v2/products/16593717304,937
#300 /api/v2/products/16593693664,923
#301 /wp-json/custom/v14,922
#302 /form.html4,912
#303 /wp-content/plugins/admin.php4,907
#304 /api/v2/products/16593689754,901
#305 /pesca/login/index.php4,896
#306 /api/v2/products/3864,889
#307 /ty.php4,851
#308 /tytyd.php4,839
#309 /index.html4,829
#310 /api/v2/marketplace/sellers/615/products/queue4,810
#311 /upl.php4,806
#312 /sites/default/files4,804
#313 /web/.env4,790
#314 /wp1/wp-includes/wlwmanifest.xml4,785
#315 /error.php4,784
#316 /graphql4,778
#317 /systembc/password.php4,773
#318 /t44,766
#319 /geoip4,764
#320 /.well-known/change-password4,752
#321 /we.php4,744
#322 /wp-admin.php4,743
#323 /x.php4,737
#324 /dev/.env4,705
#325 /.well-known/web-identity4,697
#326 /ws.php4,695
#327 /gifclass.php4,684
#328 /wp-admin/js4,673
#329 /public/.env4,672
#330 /elp.php4,671
#331 /.well-known/resource-that-should-not-exist-whose-status-code-should-not-be-2004,656
#332 /.well-known/webauthn4,654
#333 /wp-admin/includes/index.php4,632
#334 /SistemaEAD_CPREM/login/index.php4,622
#335 /wp-content/plugins/pwnd/pwnd.php4,587
#336 /sitemap.php4,583
#337 /version4,571
#338 /new/.env4,564
#339 /cgi-bin4,559
#340 /wp-admin/style.php4,531
#341 /comment-subscriptions4,515
#342 /NewFile.php4,492
#343 /wp-admin/profile.php4,478
#344 /0x.php4,461
#345 /site4,458
#346 /ab2g4,450
#347 /ab2h4,448
#348 /info4,430
#349 /alive.php4,414
#350 /api/v2/marketplace/sellers/655/products/queue4,409
#351 /teorema5054,407
#352 /wp-conflg.php4,406
#353 /ar.php4,405
#354 /wordpress/wp-login.php4,391
#355 /wp-admin/js/widgets/cloud.php4,387
#356 /admin/admin.php4,383
#357 /portal/.env4,368
#358 /api/v2/brands/47184,361
#359 /fox.php4,339
#360 /i.php4,336
#361 /.well-known/acme-challenge/mariju.php4,336
#362 /wp-admin/install.php4,304
#363 /wp-content/themes/style.php4,301
#364 /wp-admin/plugins.php4,294
#365 /wp-admin/file.php4,285
#366 /wp-admin/edit.php4,284
#367 /wp-admin/js/about.php4,273
#368 /web4,272
#369 /10.php4,250
#370 /num.php4,243
#371 /al.php4,242
#372 /wp-admin/includes/colour.php4,181
#373 /wp-admin/css/colors/blue4,158
#374 /file15.php4,148
#375 /2.php4,147
#376 /wp-json/sfwd-courses4,142
#377 /backend4,135
#378 /sts.php4,131
#379 /wp-signin.php4,130
#380 /application/.env4,072
#381 /file9.php4,046
#382 /fr4,029
#383 /wp-blog.php4,010
#384 /wp-content/plugins/pwnd/as.php4,003
#385 /test1.php3,979
#386 /aws.yml3,964
#387 /.well-known3,959
#388 /api/v2/products/16593720423,954
#389 /wp-admin/css/colors/blue/atomlib.php3,954
#390 /dashboard3,944
#391 /infos.php3,943
#392 /ini.php3,939
#393 /wp-admin/wp-admins.php3,916
#394 /gelay.php3,916
#395 /groups%22%223,893
#396 /themes/zMousse/otuz1.php3,876
#397 /api/v2/marketplace/sellers/376/products/queue3,871
#398 /not_found3,858
#399 /php8.php3,849
#400 /pp.php3,835
#401 /simular3,820
#402 /config/aws.yml3,819
#403 /fix.php3,815
#404 /gel4y.php3,806
#405 /api/v2/products/16593709403,802
#406 /api/config.env3,791
#407 /function.php3,782
#408 /wp-admin/css/about.php3,781
#409 /www/.env3,777
#410 /panel3,769
#411 /ee.php3,766
#412 /login.php3,756
#413 /wp-includes/blocks/about.php3,754
#414 /_phpinfo.php3,754
#415 /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php3,750
#416 /docker/.env3,742
#417 /wp-admin/network/network.php3,738
#418 /member-signup3,734
#419 /crm/.env3,729
#420 /ola-mundo3,723
#421 /js/.env3,715
#422 /moddofuns.php3,714
#423 /api/shared/config.env3,714
#424 /images/class-config.php3,712
#425 /xx.php3,710
#426 /wp-admin/wp-login.php3,708
#427 /fm.php3,703
#428 /wp-l0gin.php3,699
#429 /en/assets/images/logos/HTB.JPG3,692
#430 /mah/function.php3,670
#431 /customer/account/create3,670
#432 /env/.env3,669
#433 /app/config/parameters.yml3,652
#434 /contact-us3,644
#435 /wp-admin/post-new.php3,642
#436 /cron/.env3,640
#437 /cursogratuito/ola-mundo3,629
#438 /wp-content/plugins/simple-ajax-chat/includes/sac-check-user.php3,616
#439 /12.php3,611
#440 /CLA.php3,606
#441 /item/Caique-Brudden-Explorer-Fishing-Up-.html3,603
#442 /file3.php3,595
#443 /acessorios-cameras/capa-de-silicone3,590
#444 /wp-includes/wp-class.php3,586
#445 /checkout/cart/add3,568
#446 /loja/carrinho.php3,559
#447 /ss.php3,551
#448 /wp-content/plugins/about.php3,542
#449 /alfanew.php3,540
#450 /doiconvs.php3,536
#451 /rest/V1/orders3,526
#452 /api/v2/products/55183,517
#453 /dynip/f282640c3,517
#454 /api/v2/batch/11103,513
#455 /build.php3,513
#456 /local/.env3,510
#457 /wp-admin/includes3,508
#458 /epinyins.php3,506
#459 /wp-admin/js/wp-conflg.php3,506
#460 /wp-content/classwithtostring.php3,500
#461 /.well-known/acme-challenge/makeasmtp.php3,500
#462 /file7.php3,499
#463 /y.php3,493
#464 /wp-content/uploads3,480
#465 /wp-admin/css/colors/ectoplasm/about.php3,474
#466 /log.php3,474
#467 /a2.php3,473
#468 /v.php3,472
#469 /wp-admin/css/colors/blue/about.php3,470
#470 /.vscode/.env3,451
#471 /awstats/.env3,450
#472 /search3,450
#473 /.aws/config3,432
#474 /wp-json/oembed3,427
#475 /c/linha-glass/robo-aspirador3,421
#476 /wp-json/wp3,420
#477 /wp-admin/css/qPyYcxpHKCu.php3,410
#478 /site/.env3,409
#479 /cabelo/marcas-de-salao/wella-professionals/wella-professionals-invigo-color-brilliance-2-produtos3,408
#480 /test/wp-includes/wlwmanifest.xml3,408
#481 /mail.php3,404
#482 /.well-known/classwithtostring.php3,398
#483 /wp-json/sfwd-lessons3,394
#484 /inc.php3,393
#485 /api/v2/products/16593698633,384
#486 /b.php3,382
#487 /wp-aa.php3,375
#488 /settings.py3,366
#489 /wp-json/sfwd-courses/13,363
#490 /api/v2/batch/11113,363
#491 /wp-admin/autoload_classmap.php3,356
#492 /api/v2/products/5313,352
#493 /wp-admin/mah.php3,348
#494 /.env.old3,348
#495 /api/config/config.yml3,346
#496 /mini3,333
#497 /lowpr.php3,323
#498 /bak.php3,320
#499 /jp.php3,317
#500 /submissions3,317


Data was last updated on: Jan 31, 2026



Logging Research

We love logs. In this section we will share some of the data we are parsing from our logs and honeypots we have live.

Trunc Logging

Logging for fun and a good night of sleep.

  • Real time search
  • Google simple
  • Cheap
  • Just works
  • PCI compliance
Trunc Research

Latest log-based threat analysis added.

Contact us!

Do you have an idea for a research that is not here? See something wrong? Contact us at support@noc.org

Tired of price gouging
  • Clear pricing
  • No need to guess
  • Real people
  • Real logging

Simple, Affordable, Log Management and Analysis.

14 days free trial. No credit card required.