Web logs 404 analysis - all time
Dec 5, 2025
Automatically updated daily

Checking for 404 errors in your logs can reveal more than just broken links, it can also expose files and URLs that attackers are actively scanning for. To track this behavior, we set up hundreds of honeypots and analyzed live web traffic data, giving us insight into which files and URLs are being targeted across the internet.


The table bellow list the top URLs being scanned all time and is updated daily. Most of the data contain WordPress specific URLs, certain plugins and config files that attackers can use.


Rank Scanned URL Counter
#1 /wp-login.php575,627
#2 /autodiscover/autodiscover.xml266,136
#3 /xmlrpc.php139,863
#4 /.env97,103
#5 /index.php88,495
#6 /.well-known/traffic-advice87,975
#7 /sitemap.xml82,698
#8 /201257,492
#9 /40443,029
#10 /wp-json/oembed/1.0/embed42,611
#11 /.git/config40,210
#12 /module/ngmercadolivre/notificacao35,689
#13 /info.php31,273
#14 /manager/html30,575
#15 /login29,156
#16 /file.php27,064
#17 /admin.php26,082
#18 /en/AutoDiscover/autodiscover.xml24,529
#19 /wp-cron.php23,535
#20 /chosen.php23,463
#21 /wordpress22,968
#22 /about.php22,718
#23 /wp-content/plugins/hellopress/wp_filemanager.php21,853
#24 /backup21,159
#25 /wp19,848
#26 /wp-admin19,787
#27 /api/catalog_system/pub/products/search18,923
#28 /.well-known/nodeinfo17,503
#29 /old17,184
#30 /_profiler/phpinfo16,998
#31 /wp-content/plugins/fix/up.php16,992
#32 /404testpage4525d2fdc16,317
#33 /bk16,197
#34 /api/v2/marketplace/sellers/376/products/status-batch16,186
#35 /api/v2/marketplace/sellers/376/products/stock-batch16,088
#36 /api/v2/marketplace/sellers/376/products/price-batch16,073
#37 /bc16,072
#38 /alfa.php16,063
#39 /wp-includes/wlwmanifest.xml15,983
#40 /phpinfo15,919
#41 /en/autodiscover/autodiscover.xml15,703
#42 /.well-known/acme-challenge/about.php15,598
#43 /new15,320
#44 /1.php15,257
#45 /main15,213
#46 /autoload_classmap.php15,091
#47 /atomlib.php14,775
#48 /admin14,751
#49 /rest/V1/store/storeViews14,566
#50 /wp.php14,477
#51 /api/v2/categories/6513,887
#52 /api/.env13,867
#53 /lock360.php13,816
#54 /flower.php13,799
#55 /test.php13,725
#56 /file2.php13,641
#57 /classwithtostring.php13,583
#58 /web/wp-includes/wlwmanifest.xml13,472
#59 /aa.php13,407
#60 /wordpress/wp-includes/wlwmanifest.xml13,340
#61 /wp/wp-includes/wlwmanifest.xml13,111
#62 /goods.php13,099
#63 /app12,964
#64 /-/-/-/-/-/-/-/-/-/-12,915
#65 /simple.php12,737
#66 /admin/config.php12,722
#67 /blog/wp-includes/wlwmanifest.xml12,699
#68 /shop12,622
#69 /2019/wp-includes/wlwmanifest.xml12,573
#70 /debug/default/view12,550
#71 /shop/wp-includes/wlwmanifest.xml12,490
#72 /ioxi-o.php12,144
#73 /makeasmtp.php12,118
#74 /test12,055
#75 /v2/_catalog11,953
#76 /app_dev.php/_profiler/phpinfo11,903
#77 /website/wp-includes/wlwmanifest.xml11,834
#78 /AutoDiscover/autodiscover.xml11,724
#79 /backend/.env11,722
#80 /cdn-cgi/rum11,716
#81 /server-status11,704
#82 /news/wp-includes/wlwmanifest.xml11,672
#83 /pagamento/mercadopago/ipn.php11,611
#84 /web_api/auth11,581
#85 /admin/.env11,534
#86 /feed11,342
#87 /style.php11,091
#88 /.env.example11,055
#89 /.well-known/passkey-endpoints11,016
#90 /api11,013
#91 /telescope/requests10,992
#92 /cong.php10,922
#93 /edit.php10,898
#94 /contrato/wap/crons/enviar-email.php10,867
#95 /acessorios-cameras10,809
#96 /akc.php10,642
#97 /.well-known/apple-app-site-association10,356
#98 /asasx.php10,198
#99 /api/v2/categories/6410,154
#100 /api/graphql9,916
#101 /home9,898
#102 /login.action9,830
#103 /wp-plain.php9,830
#104 /inputs.php9,703
#105 /phpinfo.php9,666
#106 /css.php9,631
#107 /about9,516
#108 /as.php9,330
#109 /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application9,300
#110 /w.php9,285
#111 /radio.php9,243
#112 /user/login9,226
#113 /wp-admin/css9,191
#114 /server9,063
#115 /@vite/env9,028
#116 /_all_dbs9,024
#117 /actuator/env8,947
#118 /buy.php8,911
#119 /goat.php8,900
#120 /cgi-bin/luci/;stok=/locale8,701
#121 /wp-json/sfwd-assignment/18,681
#122 /api/v2/customers/login8,675
#123 /dropdown.php8,672
#124 /loja/login_layout.php8,612
#125 /wordpress/wp-admin/setup-config.php8,449
#126 /HNAP18,353
#127 /api/sessions8,318
#128 /lv.php8,293
#129 /gecko.php8,230
#130 /wp-sitemap.xml7,980
#131 /07550e187,958
#132 /config.php7,923
#133 /wp-content/plugins/woocommerce/includes/gateways/locks.php7,910
#134 /k.php7,854
#135 /autoload_classmap/function.php7,782
#136 /loja/catalogo.php7,759
#137 /wp-admin/images/moon.php7,756
#138 /wsa.php7,555
#139 /contato7,533
#140 /akcc.php7,502
#141 /wp-admin/setup-config.php7,499
#142 /nc4.php7,436
#143 /wiki7,431
#144 /appWP/lab/wp-admin/css/colors/blue/blue.php7,428
#145 /.well-known/acme-challenge/cloud.php7,423
#146 /php.php7,408
#147 /api/v2/auth7,370
#148 /wp-content/wp-conflg.php7,361
#149 /f35.php7,288
#150 /tinyfilemanager.php7,273
#151 /admin/index.php7,272
#152 /abcd.php7,265
#153 /gmo.php7,219
#154 /mar.php7,203
#155 /files7,192
#156 /wp-content/themes/seotheme/db.php7,168
#157 /403.php7,140
#158 /api/v3/community7,103
#159 /g/collect7,089
#160 /users.php7,062
#161 /administrator7,041
#162 /mm.php6,970
#163 /s/1313e2236313e20373e2538313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties6,958
#164 /404.php6,894
#165 /zwso.php6,890
#166 /wp-content/index.php6,838
#167 /cms6,807
#168 /doc.php6,790
#169 /system_log.php6,753
#170 /filemanager.php6,724
#171 /content.php6,537
#172 /blog6,534
#173 /.env.bak6,517
#174 /2018/wp-includes/wlwmanifest.xml6,497
#175 /index/function.php6,416
#176 /feed/mnpodcast6,413
#177 /wp-admin/wp-conflg.php6,397
#178 /wp-admin/index.php6,387
#179 /wp-admin/css/colors/blue/index.php6,375
#180 /images/images/cache.php6,374
#181 /wp-api.php6,338
#182 /wp-admin/classwithtostring.php6,328
#183 /manager.php6,318
#184 /boaform/admin/formLogin6,306
#185 /shell.php6,279
#186 /.aws/credentials6,269
#187 /g.php6,261
#188 /pb6,255
#189 /2020/wp-includes/wlwmanifest.xml6,233
#190 /api/v2/freights/3166,214
#191 /wp-setup.php6,181
#192 /wp-includes/fonts/admin.php6,160
#193 /php_info.php6,126
#194 /class.php6,121
#195 /wp-content/video6,110
#196 /api/shared/config/config.env6,086
#197 /moon.php6,076
#198 /file17.php6,044
#199 /wso.php6,036
#200 /null6,023
#201 /laravel/.env6,003
#202 /cc.php5,924
#203 /foq.php5,827
#204 /contact5,806
#205 /.well-known/acme-challenge/xmrlpc.php5,794
#206 /Form5,773
#207 /wp-admin/js/index.php5,761
#208 /app/.env5,753
#209 /.env.local5,747
#210 /wp-admin/maint/about.php5,708
#211 /assets/images/accesson.php5,652
#212 /mini.php5,649
#213 /sdk5,647
#214 /gg.php5,643
#215 /core/.env5,633
#216 /loja/busca.php5,588
#217 /evox/about5,576
#218 /images5,576
#219 /themes.php5,574
#220 /wp-includes/IXR/autoload_classmap.php5,561
#221 /admin/function.php5,536
#222 /wp-includes/fonts/index.php5,474
#223 /wp-content/about.php5,458
#224 /adminfuns.php5,457
#225 /bless.php5,442
#226 /wp-json/sfwd-lessons/15,437
#227 /install.php5,429
#228 /file5.php5,423
#229 /wp-content5,316
#230 /wp-json/sfwd-topic/15,302
#231 /undefined5,269
#232 /sk_es/vozik5,216
#233 /wp-admin/edit-tags.php5,216
#234 /default.php5,211
#235 /wp-content/plugins/wpterm.php5,198
#236 /saiga.php5,172
#237 /byp.php5,167
#238 /loja/cartService.php5,145
#239 /wp-content/plugins/WordPressCore/include.php5,109
#240 /comment.php5,096
#241 /wp-content/style.php5,078
#242 /about/function.php5,062
#243 /sitemap_index.xml5,045
#244 /.git/HEAD5,026
#245 /admin/controller/extension/extension4,972
#246 /pinfo.php4,951
#247 /bolt.php4,943
#248 /password.php4,937
#249 /uploads4,934
#250 /wp-content/autoload_classmap.php4,931
#251 /wp-json/custom/v14,922
#252 /apps/.env4,864
#253 /a.php4,864
#254 /ty.php4,800
#255 /new.php4,789
#256 /index.html4,786
#257 /api/v2/marketplace/sellers/615/products/queue4,740
#258 /wp-admin/admin-ajax.php4,732
#259 /form.html4,729
#260 /files.php4,709
#261 /m.php4,708
#262 /mah.php4,703
#263 /function/function.php4,698
#264 /web/.env4,658
#265 /error.php4,629
#266 /.git/index4,628
#267 /.env.prod4,623
#268 /upl.php4,622
#269 /we.php4,601
#270 /systembc/password.php4,594
#271 /t44,587
#272 /geoip4,585
#273 /pesca/login/index.php4,584
#274 /.well-known/change-password4,566
#275 /api/v2/products/3864,566
#276 /wp-content/themes/about.php4,546
#277 /.well-known/web-identity4,517
#278 /graphql4,509
#279 /wp-admin/js/autoload_classmap.php4,502
#280 /13.php4,497
#281 /s.php4,494
#282 /.well-known/webauthn4,474
#283 /.well-known/resource-that-should-not-exist-whose-status-code-should-not-be-2004,471
#284 /wp1/wp-includes/wlwmanifest.xml4,469
#285 /wp-editor.php4,445
#286 /version4,436
#287 /site4,428
#288 /sites/default/files4,422
#289 /tytyd.php4,414
#290 /public/.env4,410
#291 /new/.env4,407
#292 /gifclass.php4,393
#293 /x.php4,392
#294 /dev/.env4,358
#295 /sitemap.php4,354
#296 /wp-admin/js/widgets/cloud.php4,344
#297 /admin/admin.php4,344
#298 /wp-admin/style.php4,344
#299 /fox.php4,339
#300 /ws.php4,339
#301 /wp-content/admin.php4,339
#302 /wp-admin/profile.php4,337
#303 /.well-known/acme-challenge/mariju.php4,319
#304 /222.php4,306
#305 /ar.php4,287
#306 /wordpress/wp-login.php4,284
#307 /wp-admin/file.php4,277
#308 /info4,251
#309 /NewFile.php4,246
#310 /ab2g4,238
#311 /ab2h4,236
#312 /web4,227
#313 /wp-admin/install.php4,213
#314 /SistemaEAD_CPREM/login/index.php4,209
#315 /alive.php4,203
#316 /teorema5054,196
#317 /item.php4,193
#318 /wp-admin/plugins.php4,189
#319 /wp-admin.php4,185
#320 /wp-trackback.php4,169
#321 /wp-json/sfwd-courses4,142
#322 /i.php4,136
#323 /wp-admin/edit.php4,133
#324 /10.php4,119
#325 /backend4,113
#326 /wp-content/themes/admin.php4,109
#327 /wp-content/themes/style.php4,099
#328 /file15.php4,095
#329 /wp-admin/js/about.php4,082
#330 /al.php4,078
#331 /portal/.env4,059
#332 /xmrlpc.php4,018
#333 /sts.php3,997
#334 /wp-admin/includes/index.php3,946
#335 /application/.env3,937
#336 /file9.php3,935
#337 /0x.php3,929
#338 /infos.php3,925
#339 /dashboard3,895
#340 /themes/zMousse/otuz1.php3,873
#341 /api/v2/marketplace/sellers/376/products/queue3,871
#342 /fix.php3,815
#343 /api/v2/marketplace/sellers/655/products/queue3,815
#344 /config/aws.yml3,753
#345 /ini.php3,752
#346 /panel3,750
#347 /function.php3,748
#348 /pp.php3,742
#349 /wp-includes/blocks/about.php3,736
#350 /wp-admin/network/network.php3,735
#351 /php8.php3,732
#352 /member-signup3,731
#353 /api/config.env3,723
#354 /groups%22%223,720
#355 /moddofuns.php3,714
#356 /wp-admin/wp-login.php3,703
#357 /wp-admin/js3,703
#358 /images/class-config.php3,694
#359 /wp-l0gin.php3,672
#360 /www/.env3,659
#361 /_phpinfo.php3,650
#362 /js/.env3,648
#363 /api/shared/config.env3,647
#364 /ola-mundo3,640
#365 /crm/.env3,636
#366 /contact-us3,626
#367 /2.php3,622
#368 /wp-admin/post-new.php3,618
#369 /login.php3,602
#370 /ee.php3,601
#371 /wp-conflg.php3,599
#372 /acessorios-cameras/capa-de-silicone3,590
#373 /gel4y.php3,586
#374 /wp-includes/wp-class.php3,551
#375 /file3.php3,549
#376 /xx.php3,542
#377 /doiconvs.php3,536
#378 /app/config/parameters.yml3,536
#379 /api/v2/brands/47183,532
#380 /CLA.php3,519
#381 /api/v2/products/55183,517
#382 /epinyins.php3,506
#383 /aws.yml3,500
#384 /test1.php3,495
#385 /cursogratuito/ola-mundo3,488
#386 /dynip/f282640c3,486
#387 /.well-known/acme-challenge/makeasmtp.php3,483
#388 /fr3,473
#389 /wp-admin/css/colors/ectoplasm/about.php3,471
#390 /docker/.env3,471
#391 /en/assets/images/logos/HTB.JPG3,463
#392 /wp-admin/css/colors/blue3,459
#393 /item/Caique-Brudden-Explorer-Fishing-Up-.html3,449
#394 /file7.php3,437
#395 /c/linha-glass/robo-aspirador3,421
#396 /cron/.env3,421
#397 /env/.env3,419
#398 /wp-admin/css/qPyYcxpHKCu.php3,410
#399 /cabelo/marcas-de-salao/wella-professionals/wella-professionals-invigo-color-brilliance-2-produtos3,408
#400 /loja/carrinho.php3,400
#401 /wp-json/oembed3,395
#402 /wp-json/sfwd-lessons3,394
#403 /local/.env3,393
#404 /12.php3,390
#405 /wp-json/wp3,378
#406 /wp-json/sfwd-courses/13,363
#407 /y.php3,363
#408 /.aws/config3,363
#409 /a2.php3,361
#410 /gelay.php3,360
#411 /.well-known/classwithtostring.php3,359
#412 /upload/banner3,359
#413 /wp-admin/css/colors/blue/about.php3,351
#414 /v.php3,351
#415 /inc.php3,346
#416 /.well-known3,346
#417 /wp-admin/mah.php3,345
#418 /wp-admin/js/wp-conflg.php3,340
#419 /wp-aa.php3,338
#420 /wp-content/plugins/pwnd/pwnd.php3,333
#421 /fm.php3,313
#422 /not_found3,304
#423 /site/.env3,294
#424 /b.php3,290
#425 /api/config/config.yml3,287
#426 /simular3,287
#427 /alfanew.php3,272
#428 /ahax.php3,264
#429 /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php3,255
#430 /wp-json/sfwd-topic3,254
#431 /wp-admin/chosen.php3,252
#432 /api/v2/batch/11103,248
#433 /.vscode/.env3,243
#434 /.AWS_/credentials3,230
#435 /prod/.env3,228
#436 /pages.php3,215
#437 /settings.py3,214
#438 /.env.old3,210
#439 /wp-includes/about.php3,197
#440 /cgi-bin3,191
#441 /tool/view/phpinfo.view.php3,189
#442 /api/v2/marketplace/sellers/376/products/batch3,175
#443 /.env.production.local3,160
#444 /log.php3,159
#445 /setup.php3,147
#446 /test/wp-includes/wlwmanifest.xml3,147
#447 /dashboard/phpinfo.php3,143
#448 /awstats/.env3,140
#449 /.env.stage3,135
#450 /post.php3,130
#451 /.well-known/acme-challenge/doc.php3,123
#452 /busca3,123
#453 /mail.php3,122
#454 /CDGServer3/SystemConfig3,121
#455 /wp-signin.php3,106
#456 /cabelos/creme-tratamento-silicon-mix3,104
#457 /api/objects/codes.php.save3,102
#458 /geju.php3,100
#459 /api/v2/batch/11113,097
#460 /wp-content/plugins/about.php3,096
#461 /build.php3,086
#462 /ss.php3,082
#463 /ms-edit.php3,077
#464 /conf/.env3,076
#465 /wp-content/uploads/de_fb_uploads/b.php3,072
#466 /loja/arquivos/1049375/sitemaps/sitemap_1.xml3,044
#467 /wp-config.php.bak3,042
#468 /categoria-produto/aneis/feminino3,041
#469 /search3,041
#470 /wp-admin/admin.php3,020
#471 /file6.php3,013
#472 /wp-admin/wp-admins.php3,009
#473 /main/.env3,007
#474 /ova.php3,004
#475 /bak.php3,004
#476 /jmx-console3,002
#477 /wp-admin/css/colors/blue/atomlib.php2,994
#478 /server-info.php2,984
#479 /plugins.php2,982
#480 /bugz.php2,979
#481 /assets/images/doc.php2,978
#482 /wp-includes/ID3/index.php2,973
#483 /new/.env.staging2,968
#484 /wp-admin/wp.php2,967
#485 /robots.php2,965
#486 /noc-cdn2,965
#487 /development/.env2,962
#488 /mail/.env2,961
#489 /.env.production2,956
#490 /wp-content/plugins/pwnd/as.php2,954
#491 /aws-secret.yaml2,952
#492 /h.php2,947
#493 /wp-content/classwithtostring.php2,936
#494 /.well-known/acme-challenge/index.php2,930
#495 /mailer/.env2,927
#496 /site/wp-includes/wlwmanifest.xml2,914
#497 /wp-content/plugins/autoload_classmap.php2,909
#498 /ALFA_DATA/alfacgiapi/perl.alfa2,909
#499 /wp-json/sfwd-assignment2,899
#500 /lowpr.php2,898


Data was last updated on: Dec 5, 2025



Logging Research

We love logs. In this section we will share some of the data we are parsing from our logs and honeypots we have live.

Trunc Logging

Logging for fun and a good night of sleep.

  • Real time search
  • Google simple
  • Cheap
  • Just works
  • PCI compliance
Trunc Research

Latest log-based threat analysis added.

Contact us!

Do you have an idea for a research that is not here? See something wrong? Contact us at support@noc.org

Tired of price gouging
  • Clear pricing
  • No need to guess
  • Real people
  • Real logging

Simple, Affordable, Log Management and Analysis.

14 days free trial. No credit card required.