Web logs 404 analysis - all time
Jan 18, 2026
Automatically updated daily

Checking for 404 errors in your logs can reveal more than just broken links, it can also expose files and URLs that attackers are actively scanning for. To track this behavior, we set up hundreds of honeypots and analyzed live web traffic data, giving us insight into which files and URLs are being targeted across the internet.


The table bellow list the top URLs being scanned all time and is updated daily. Most of the data contain WordPress specific URLs, certain plugins and config files that attackers can use.


Rank Scanned URL Counter
#1 /wp-login.php592,724
#2 /autodiscover/autodiscover.xml279,702
#3 /xmlrpc.php142,504
#4 /index.php103,915
#5 /.env101,436
#6 /.well-known/traffic-advice96,532
#7 /sitemap.xml84,543
#8 /201257,492
#9 /api/v2/auth48,642
#10 /40445,812
#11 /wp-json/oembed/1.0/embed45,762
#12 /.git/config42,313
#13 /module/ngmercadolivre/notificacao36,421
#14 /info.php34,356
#15 /manager/html32,846
#16 /file.php31,044
#17 /admin.php30,528
#18 /login30,153
#19 /about.php26,759
#20 /chosen.php26,255
#21 /en/AutoDiscover/autodiscover.xml25,403
#22 /wp-cron.php24,848
#23 /wordpress23,647
#24 /wp-content/plugins/hellopress/wp_filemanager.php22,229
#25 /backup22,209
#26 /wp-admin21,103
#27 /wp20,483
#28 /api/catalog_system/pub/products/search18,944
#29 /alfa.php18,151
#30 /old17,797
#31 /.well-known/nodeinfo17,615
#32 /wp-content/plugins/fix/up.php17,301
#33 /_profiler/phpinfo17,280
#34 /classwithtostring.php16,962
#35 /wp.php16,929
#36 /404testpage4525d2fdc16,659
#37 /wp-includes/wlwmanifest.xml16,556
#38 /1.php16,307
#39 /phpinfo16,291
#40 /bk16,276
#41 /en/autodiscover/autodiscover.xml16,210
#42 /api/v2/marketplace/sellers/376/products/status-batch16,186
#43 /aa.php16,174
#44 /ioxi-o.php16,159
#45 /atomlib.php16,118
#46 /goods.php16,101
#47 /api/v2/marketplace/sellers/376/products/stock-batch16,088
#48 /api/v2/marketplace/sellers/376/products/price-batch16,073
#49 /bc16,072
#50 /new15,878
#51 /autoload_classmap.php15,824
#52 /.well-known/acme-challenge/about.php15,756
#53 /admin15,740
#54 /.well-known/passkey-endpoints15,703
#55 /api/.env15,460
#56 /main15,213
#57 /rest/V1/store/storeViews14,919
#58 /simple.php14,556
#59 /test.php14,503
#60 /flower.php14,164
#61 /lock360.php14,012
#62 /file2.php13,972
#63 /web/wp-includes/wlwmanifest.xml13,958
#64 /api/v2/categories/6513,887
#65 /edit.php13,837
#66 /wordpress/wp-includes/wlwmanifest.xml13,822
#67 /wp/wp-includes/wlwmanifest.xml13,594
#68 /admin/config.php13,589
#69 /-/-/-/-/-/-/-/-/-/-13,289
#70 /shop13,254
#71 /app_dev.php/_profiler/phpinfo13,194
#72 /blog/wp-includes/wlwmanifest.xml13,164
#73 /backend/.env13,159
#74 /app13,078
#75 /2019/wp-includes/wlwmanifest.xml13,028
#76 /shop/wp-includes/wlwmanifest.xml12,939
#77 /admin/.env12,898
#78 /debug/default/view12,781
#79 /web_api/auth12,544
#80 /cdn-cgi/rum12,524
#81 /cong.php12,492
#82 /AutoDiscover/autodiscover.xml12,353
#83 /.env.example12,345
#84 /makeasmtp.php12,339
#85 /website/wp-includes/wlwmanifest.xml12,279
#86 /pagamento/mercadopago/ipn.php12,181
#87 /v2/_catalog12,170
#88 /news/wp-includes/wlwmanifest.xml12,113
#89 /test12,110
#90 /server-status11,953
#91 /feed11,904
#92 /buy.php11,895
#93 /style.php11,794
#94 /contrato/wap/crons/enviar-email.php11,729
#95 /api11,375
#96 /abcd.php11,234
#97 /telescope/requests11,213
#98 /radio.php11,171
#99 /akc.php11,079
#100 /.well-known/apple-app-site-association11,054
#101 /asasx.php10,963
#102 /autoload_classmap/function.php10,947
#103 /akcc.php10,938
#104 /inputs.php10,858
#105 /acessorios-cameras10,809
#106 /saiga.php10,689
#107 /wp-plain.php10,340
#108 /dropdown.php10,276
#109 /api/v2/categories/6410,248
#110 /wp-admin/css10,239
#111 /api/graphql10,100
#112 /css.php10,046
#113 /k.php9,982
#114 /login.action9,958
#115 /phpinfo.php9,955
#116 /home9,942
#117 /as.php9,710
#118 /about9,697
#119 /user/login9,607
#120 /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application9,417
#121 /w.php9,355
#122 /api/sessions9,308
#123 /server9,179
#124 /@vite/env9,131
#125 /_all_dbs9,131
#126 /actuator/env9,084
#127 /api/v2/customers/login9,058
#128 /bless.php9,016
#129 /adminfuns.php8,993
#130 /404.php8,959
#131 /[object%20Object]8,935
#132 /goat.php8,903
#133 /loja/login_layout.php8,878
#134 /cgi-bin/luci/;stok=/locale8,702
#135 /wp-json/sfwd-assignment/18,681
#136 /HNAP18,668
#137 /wordpress/wp-admin/setup-config.php8,560
#138 /lv.php8,495
#139 /files8,459
#140 /gecko.php8,427
#141 /php.php8,342
#142 /loja/catalogo.php8,331
#143 /config.php8,251
#144 /wp-admin/classwithtostring.php8,092
#145 /wp-sitemap.xml8,038
#146 /07550e188,022
#147 /manager.php7,958
#148 /.well-known/acme-challenge/cloud.php7,948
#149 /administrator7,948
#150 /bolt.php7,930
#151 /wp-content/plugins/woocommerce/includes/gateways/locks.php7,910
#152 /appWP/lab/wp-admin/css/colors/blue/blue.php7,906
#153 /wp-content/index.php7,892
#154 /403.php7,865
#155 /themes.php7,810
#156 /wp-admin/images/moon.php7,756
#157 /contato7,680
#158 /nc4.php7,675
#159 /wp-admin/setup-config.php7,614
#160 /wsa.php7,602
#161 /wiki7,485
#162 /f35.php7,446
#163 /wp-content/themes/seotheme/db.php7,421
#164 /wp-content/wp-conflg.php7,419
#165 /gg.php7,392
#166 /admin/index.php7,381
#167 /gmo.php7,358
#168 /g/collect7,346
#169 /index/function.php7,320
#170 /tinyfilemanager.php7,311
#171 /mar.php7,249
#172 /users.php7,128
#173 /zwso.php7,118
#174 /api/v3/community7,103
#175 /content.php7,076
#176 /s/1313e2236313e20373e2538313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties7,037
#177 /wp-admin/index.php7,036
#178 /mm.php6,977
#179 /blog6,960
#180 /images/images/cache.php6,957
#181 /filemanager.php6,950
#182 /doc.php6,947
#183 /wp-content/autoload_classmap.php6,944
#184 /null6,908
#185 /upload/banner6,884
#186 /pb6,855
#187 /images6,845
#188 /class.php6,821
#189 /system_log.php6,817
#190 /2018/wp-includes/wlwmanifest.xml6,812
#191 /cms6,808
#192 /new.php6,749
#193 /shell.php6,748
#194 /wp-content/admin.php6,677
#195 /.env.bak6,644
#196 /wp-admin/js/index.php6,543
#197 /wp-content/video6,536
#198 /wp-admin/css/colors/blue/index.php6,532
#199 /feed/mnpodcast6,527
#200 /boaform/admin/formLogin6,522
#201 /wp-content/themes/about.php6,478
#202 /wp-admin/wp-conflg.php6,469
#203 /cc.php6,464
#204 /install.php6,449
#205 /mah.php6,446
#206 /wp-admin/js/autoload_classmap.php6,426
#207 /moon.php6,422
#208 /wp-content/themes/admin.php6,418
#209 /.aws/credentials6,375
#210 /2020/wp-includes/wlwmanifest.xml6,366
#211 /g.php6,360
#212 /api/v2/freights/3166,350
#213 /wp-api.php6,339
#214 /wso.php6,305
#215 /wp-includes/fonts/admin.php6,235
#216 /rest/V1/inventory/source-items6,203
#217 /wp-json/mod/v1/check-site6,198
#218 /php_info.php6,197
#219 /mini.php6,196
#220 /wp-setup.php6,182
#221 /api/shared/config/config.env6,117
#222 /laravel/.env6,094
#223 /file17.php6,052
#224 /.well-known/acme-challenge/xmrlpc.php6,041
#225 /app/.env5,997
#226 /ahax.php5,964
#227 /loja/busca.php5,911
#228 /contact5,895
#229 /sdk5,893
#230 /.env.local5,843
#231 /foq.php5,827
#232 /evox/about5,818
#233 /admin/function.php5,812
#234 /wp-content/about.php5,796
#235 /wp-admin/maint/about.php5,789
#236 /222.php5,784
#237 /Form5,778
#238 /file5.php5,771
#239 /core/.env5,733
#240 /assets/images/accesson.php5,665
#241 /wp-content/style.php5,596
#242 /admin/controller/extension/extension5,593
#243 /sitemap_index.xml5,587
#244 /wp-includes/fonts/index.php5,580
#245 /wp-includes/IXR/autoload_classmap.php5,561
#246 /uploads5,545
#247 /xmrlpc.php5,507
#248 /default.php5,498
#249 /wp-content5,475
#250 /wp-editor.php5,463
#251 /wp-json/sfwd-lessons/15,437
#252 /undefined5,375
#253 /item.php5,327
#254 /about/function.php5,320
#255 /byp.php5,319
#256 /loja/cartService.php5,311
#257 /wp-json/sfwd-topic/15,302
#258 /13.php5,253
#259 /wp-admin/edit-tags.php5,252
#260 /sk_es/vozik5,216
#261 /wp-content/plugins/WordPressCore/include.php5,209
#262 /wp-content/plugins/wpterm.php5,198
#263 /comment.php5,183
#264 /function/function.php5,182
#265 /pinfo.php5,165
#266 /a.php5,157
#267 /s.php5,104
#268 /wp-admin/admin-ajax.php5,094
#269 /.git/HEAD5,079
#270 /.env.prod5,075
#271 /password.php5,054
#272 /files.php4,943
#273 /wp-json/custom/v14,922
#274 /wp-good.php4,920
#275 /apps/.env4,914
#276 /m.php4,910
#277 /api/v2/products/3864,889
#278 /form.html4,850
#279 /pesca/login/index.php4,842
#280 /ty.php4,829
#281 /index.html4,817
#282 /api/v2/marketplace/sellers/615/products/queue4,810
#283 /.well-known/change-password4,752
#284 /upl.php4,740
#285 /web/.env4,734
#286 /tytyd.php4,731
#287 /graphql4,713
#288 /systembc/password.php4,711
#289 /t44,704
#290 /geoip4,702
#291 /.well-known/web-identity4,697
#292 /error.php4,695
#293 /wp1/wp-includes/wlwmanifest.xml4,689
#294 /we.php4,687
#295 /sites/default/files4,659
#296 /.well-known/resource-that-should-not-exist-whose-status-code-should-not-be-2004,656
#297 /.well-known/webauthn4,654
#298 /.git/index4,637
#299 /x.php4,621
#300 /public/.env4,621
#301 /wp-admin/includes/index.php4,607
#302 /gifclass.php4,598
#303 /wp-admin/js4,560
#304 /wp-content/plugins/pwnd/pwnd.php4,541
#305 /sitemap.php4,538
#306 /SistemaEAD_CPREM/login/index.php4,531
#307 /dev/.env4,512
#308 /wp-content/plugins/admin.php4,499
#309 /wp-admin.php4,494
#310 /wp-admin/style.php4,487
#311 /wp-trackback.php4,483
#312 /comment-subscriptions4,476
#313 /NewFile.php4,457
#314 /new/.env4,456
#315 /version4,450
#316 /site4,432
#317 /ws.php4,426
#318 /wp-admin/profile.php4,421
#319 /ab2g4,400
#320 /ab2h4,398
#321 /info4,396
#322 /ar.php4,377
#323 /alive.php4,365
#324 /teorema5054,358
#325 /wp-admin/js/widgets/cloud.php4,347
#326 /admin/admin.php4,344
#327 /fox.php4,339
#328 /wordpress/wp-login.php4,339
#329 /i.php4,326
#330 /.well-known/acme-challenge/mariju.php4,319
#331 /0x.php4,299
#332 /wp-admin/file.php4,284
#333 /api/v2/products/16593714624,278
#334 /wp-conflg.php4,276
#335 /wp-admin/install.php4,271
#336 /web4,269
#337 /wp-admin/plugins.php4,268
#338 /api/v2/products/16593720224,260
#339 /api/v2/products/16593701434,252
#340 /wp-content/themes/style.php4,251
#341 /api/v2/products/16593706904,249
#342 /api/v2/products/16593705404,243
#343 /api/v2/products/16593711944,242
#344 /api/v2/products/16593695924,241
#345 /api/v2/products/16593690384,238
#346 /api/v2/marketplace/sellers/655/products/queue4,235
#347 /api/v2/products/16593706494,229
#348 /api/v2/products/16593710294,224
#349 /api/v2/products/16593718844,224
#350 /api/v2/products/16593694854,224
#351 /api/v2/products/16593719504,223
#352 /api/v2/products/16593703154,219
#353 /api/v2/products/16593699414,214
#354 /wp-admin/edit.php4,213
#355 /api/v2/products/16593693184,211
#356 /api/v2/products/16593712174,207
#357 /api/v2/products/16593714894,199
#358 /api/v2/products/16593705394,198
#359 /wp-admin/js/about.php4,196
#360 /api/v2/products/16593697654,195
#361 /api/v2/products/16593693664,188
#362 /api/v2/products/16593717304,184
#363 /wp-admin/includes/colour.php4,181
#364 /api/v2/products/16593689754,168
#365 /wp-admin/css/colors/blue4,156
#366 /wp-json/sfwd-courses4,142
#367 /10.php4,128
#368 /portal/.env4,128
#369 /al.php4,117
#370 /backend4,113
#371 /wp-signin.php4,113
#372 /api/v2/brands/47184,109
#373 /file15.php4,099
#374 /elp.php4,099
#375 /application/.env4,030
#376 /fr4,026
#377 /sts.php4,015
#378 /num.php3,999
#379 /file9.php3,992
#380 /wp-content/plugins/pwnd/as.php3,987
#381 /api/v2/products/16593720423,954
#382 /infos.php3,942
#383 /dashboard3,929
#384 /wp-blog.php3,925
#385 /wp-admin/wp-admins.php3,916
#386 /gelay.php3,916
#387 /wp-admin/css/colors/blue/atomlib.php3,903
#388 /cgi-bin3,898
#389 /aws.yml3,890
#390 /themes/zMousse/otuz1.php3,876
#391 /2.php3,876
#392 /api/v2/marketplace/sellers/376/products/queue3,871
#393 /groups%22%223,855
#394 /ini.php3,824
#395 /fix.php3,815
#396 /php8.php3,807
#397 /gel4y.php3,806
#398 /api/v2/products/16593709403,802
#399 /config/aws.yml3,784
#400 /function.php3,775
#401 /wp-admin/css/about.php3,772
#402 /ee.php3,764
#403 /pp.php3,763
#404 /wp-includes/blocks/about.php3,754
#405 /api/config.env3,751
#406 /panel3,750
#407 /login.php3,750
#408 /wp-admin/network/network.php3,738
#409 /member-signup3,734
#410 /www/.env3,734
#411 /simular3,727
#412 /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php3,726
#413 /moddofuns.php3,714
#414 /images/class-config.php3,711
#415 /wp-admin/wp-login.php3,706
#416 /docker/.env3,697
#417 /ola-mundo3,695
#418 /wp-l0gin.php3,693
#419 /.well-known3,690
#420 /crm/.env3,683
#421 /js/.env3,680
#422 /test1.php3,678
#423 /_phpinfo.php3,675
#424 /api/shared/config.env3,673
#425 /mah/function.php3,665
#426 /xx.php3,657
#427 /fm.php3,650
#428 /wp-admin/post-new.php3,639
#429 /contact-us3,633
#430 /env/.env3,626
#431 /wp-content/plugins/simple-ajax-chat/includes/sac-check-user.php3,616
#432 /customer/account/create3,608
#433 /cron/.env3,605
#434 /cursogratuito/ola-mundo3,603
#435 /acessorios-cameras/capa-de-silicone3,590
#436 /12.php3,584
#437 /wp-includes/wp-class.php3,582
#438 /file3.php3,575
#439 /item/Caique-Brudden-Explorer-Fishing-Up-.html3,562
#440 /app/config/parameters.yml3,561
#441 /CLA.php3,555
#442 /doiconvs.php3,536
#443 /en/assets/images/logos/HTB.JPG3,527
#444 /loja/carrinho.php3,518
#445 /api/v2/products/55183,517
#446 /epinyins.php3,506
#447 /wp-content/classwithtostring.php3,489
#448 /dynip/f282640c3,486
#449 /.well-known/acme-challenge/makeasmtp.php3,483
#450 /wp-admin/css/colors/ectoplasm/about.php3,474
#451 /v.php3,472
#452 /local/.env3,468
#453 /file7.php3,467
#454 /api/v2/batch/11103,436
#455 /wp-json/oembed3,427
#456 /alfanew.php3,424
#457 /wp-content/plugins/about.php3,424
#458 /wp-admin/js/wp-conflg.php3,423
#459 /wp-admin/css/colors/blue/about.php3,422
#460 /c/linha-glass/robo-aspirador3,421
#461 /wp-json/wp3,420
#462 /wp-admin/css/qPyYcxpHKCu.php3,410
#463 /cabelo/marcas-de-salao/wella-professionals/wella-professionals-invigo-color-brilliance-2-produtos3,408
#464 /.vscode/.env3,408
#465 /awstats/.env3,407
#466 /wp-json/sfwd-lessons3,394
#467 /.aws/config3,393
#468 /inc.php3,392
#469 /api/v2/products/16593698633,384
#470 /not_found3,384
#471 /b.php3,382
#472 /a2.php3,380
#473 /wp-aa.php3,375
#474 /rest/V1/orders3,372
#475 /y.php3,370
#476 /site/.env3,366
#477 /wp-json/sfwd-courses/13,363
#478 /.well-known/classwithtostring.php3,362
#479 /wp-admin/autoload_classmap.php3,351
#480 /wp-admin/mah.php3,348
#481 /mini3,333
#482 /test/wp-includes/wlwmanifest.xml3,323
#483 /build.php3,320
#484 /settings.py3,317
#485 /mail.php3,315
#486 /api/config/config.yml3,312
#487 /api/v2/batch/11113,285
#488 /.env.old3,279
#489 /prod/.env3,274
#490 /log.php3,258
#491 /wp-admin/includes3,257
#492 /wp-admin/chosen.php3,255
#493 /wp-json/sfwd-topic3,254
#494 /.AWS_/credentials3,253
#495 /search3,249
#496 /CDGServer3/SystemConfig3,246
#497 /wp-includes/about.php3,236
#498 /jp.php3,231
#499 /pages.php3,218
#500 /ss.php3,210


Data was last updated on: Jan 18, 2026



Logging Research

We love logs. In this section we will share some of the data we are parsing from our logs and honeypots we have live.

Trunc Logging

Logging for fun and a good night of sleep.

  • Real time search
  • Google simple
  • Cheap
  • Just works
  • PCI compliance
Trunc Research

Latest log-based threat analysis added.

Contact us!

Do you have an idea for a research that is not here? See something wrong? Contact us at support@noc.org

Tired of price gouging
  • Clear pricing
  • No need to guess
  • Real people
  • Real logging

Simple, Affordable, Log Management and Analysis.

14 days free trial. No credit card required.