Web logs 404 analysis - all time
Sep 17, 2025
Automatically updated daily

Checking for 404 errors in your logs can reveal more than just broken links, it can also expose files and URLs that attackers are actively scanning for. To track this behavior, we set up hundreds of honeypots and analyzed live web traffic data, giving us insight into which files and URLs are being targeted across the internet.


The table bellow list the top URLs being scanned all time and is updated daily. Most of the data contain WordPress specific URLs, certain plugins and config files that attackers can use.


Rank Scanned URL Counter
#1 /wp-login.php333,233
#2 /autodiscover/autodiscover.xml149,876
#3 /xmlrpc.php76,174
#4 /index.php60,512
#5 /.env51,769
#6 /sitemap.xml40,526
#7 /40429,937
#8 /wp-json/oembed/1.0/embed26,091
#9 /.git/config21,169
#10 /.well-known/traffic-advice20,858
#11 /info.php19,641
#12 /api/catalog_system/pub/products/search18,801
#13 /file.php18,681
#14 /wp-content/plugins/hellopress/wp_filemanager.php17,019
#15 /admin.php16,160
#16 /chosen.php15,206
#17 /en/AutoDiscover/autodiscover.xml14,680
#18 /wordpress14,365
#19 /about.php14,052
#20 /.well-known/nodeinfo13,329
#21 /wp12,990
#22 /bk12,418
#23 /backup12,365
#24 /bc12,291
#25 /wp-admin11,987
#26 /alfa.php11,642
#27 /.well-known/acme-challenge/about.php11,578
#28 /login11,534
#29 /module/ngmercadolivre/notificacao11,493
#30 /_profiler/phpinfo11,333
#31 /autoload_classmap.php10,827
#32 /old10,675
#33 /wp.php10,510
#34 /acessorios-cameras10,453
#35 /file2.php10,368
#36 /simple.php10,020
#37 /main9,986
#38 /lock360.php9,913
#39 /goods.php9,784
#40 /atomlib.php9,778
#41 /new9,540
#42 /1.php9,424
#43 /classwithtostring.php9,346
#44 /phpinfo9,258
#45 /aa.php9,210
#46 /admin8,734
#47 /-/-/-/-/-/-/-/-/-/-8,658
#48 /edit.php8,608
#49 /makeasmtp.php8,560
#50 /flower.php8,435
#51 /ioxi-o.php8,355
#52 /.well-known/apple-app-site-association8,174
#53 /wp-content/plugins/woocommerce/includes/gateways/locks.php7,910
#54 /wp-content/plugins/fix/up.php7,704
#55 /test.php7,656
#56 /debug/default/view7,650
#57 /w.php7,642
#58 /inputs.php7,461
#59 /cgi-bin/luci/;stok=/locale7,353
#60 /asasx.php7,293
#61 /cong.php7,259
#62 /wp-includes/wlwmanifest.xml7,243
#63 /en/autodiscover/autodiscover.xml7,214
#64 /goat.php7,132
#65 /radio.php7,081
#66 /wp-cron.php7,037
#67 /as.php7,026
#68 /server-status6,937
#69 /api/v3/community6,780
#70 /v2/_catalog6,761
#71 /gecko.php6,754
#72 /wordpress/wp-admin/setup-config.php6,716
#73 /config.php6,628
#74 /akc.php6,606
#75 /wp-admin/images/moon.php6,582
#76 /css.php6,563
#77 /AutoDiscover/autodiscover.xml6,411
#78 /telescope/requests6,342
#79 /feed6,313
#80 /autoload_classmap/function.php6,113
#81 /f35.php6,095
#82 /404testpage4525d2fdc6,094
#83 /dropdown.php6,040
#84 /api6,028
#85 /wsa.php6,025
#86 /k.php6,005
#87 /style.php5,997
#88 /mm.php5,993
#89 /web/wp-includes/wlwmanifest.xml5,939
#90 /web_api/auth5,932
#91 /.well-known/acme-challenge/cloud.php5,928
#92 /users.php5,919
#93 /wordpress/wp-includes/wlwmanifest.xml5,881
#94 /wp/wp-includes/wlwmanifest.xml5,804
#95 /wp-content/wp-conflg.php5,741
#96 /403.php5,715
#97 /wp-plain.php5,702
#98 /buy.php5,702
#99 /wp-admin/classwithtostring.php5,681
#100 /login.action5,641
#101 /lv.php5,632
#102 /blog/wp-includes/wlwmanifest.xml5,607
#103 /wp-admin/setup-config.php5,595
#104 /wp-admin/wp-conflg.php5,580
#105 /home5,533
#106 /wp-api.php5,489
#107 /2019/wp-includes/wlwmanifest.xml5,475
#108 /tinyfilemanager.php5,468
#109 /api/graphql5,454
#110 /php.php5,441
#111 /shop/wp-includes/wlwmanifest.xml5,427
#112 /404.php5,395
#113 /mar.php5,379
#114 /loja/login_layout.php5,369
#115 /test5,342
#116 /filemanager.php5,334
#117 /about5,323
#118 /wp-includes/fonts/admin.php5,301
#119 /website/wp-includes/wlwmanifest.xml5,298
#120 /wp-setup.php5,289
#121 /system_log.php5,275
#122 /api/shared/config/config.env5,264
#123 /wp-admin/css/colors/blue/index.php5,244
#124 /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application5,237
#125 /cc.php5,226
#126 /news/wp-includes/wlwmanifest.xml5,192
#127 /wp-content/index.php5,163
#128 /actuator/env5,141
#129 /_all_dbs5,133
#130 /wp-admin/maint/about.php5,125
#131 /phpinfo.php5,111
#132 /server5,106
#133 /class.php5,087
#134 /index/function.php5,048
#135 /.well-known/acme-challenge/xmrlpc.php5,029
#136 /@vite/env5,006
#137 /api/v2/categories/644,893
#138 /file17.php4,883
#139 /g.php4,818
#140 /admin/index.php4,793
#141 /appWP/lab/wp-admin/css/colors/blue/blue.php4,765
#142 /wp-admin/js/index.php4,752
#143 /api/.env4,737
#144 /.well-known/passkey-endpoints4,731
#145 /admin/function.php4,726
#146 /wp-includes/IXR/autoload_classmap.php4,709
#147 /gmo.php4,676
#148 /mini.php4,663
#149 /app_dev.php/_profiler/phpinfo4,661
#150 /HNAP14,604
#151 /wp-content/about.php4,562
#152 /wp-includes/fonts/index.php4,561
#153 /wso.php4,554
#154 /gg.php4,528
#155 /api/v2/categories/654,464
#156 /file5.php4,440
#157 /contato4,407
#158 /wp-content/themes/seotheme/db.php4,406
#159 /wp-content/autoload_classmap.php4,394
#160 /php_info.php4,341
#161 /wp-admin/css4,334
#162 /doc.php4,299
#163 /wp-admin/js/widgets/cloud.php4,268
#164 /about/function.php4,267
#165 /wp-admin/file.php4,240
#166 /wp-admin/js/autoload_classmap.php4,220
#167 /images/images/cache.php4,176
#168 /wp-admin/index.php4,156
#169 /wp-content/plugins/wpterm.php4,145
#170 /ty.php4,130
#171 /wp-json/custom/v14,107
#172 /rest/V1/store/storeViews4,106
#173 /byp.php4,095
#174 /nc4.php4,045
#175 /wordpress/wp-login.php3,990
#176 /manager.php3,986
#177 /m.php3,960
#178 /zwso.php3,957
#179 /.well-known/change-password3,955
#180 /.well-known/web-identity3,947
#181 /user/login3,934
#182 /themes.php3,911
#183 /.well-known/webauthn3,910
#184 /s/1313e2236313e20373e2538313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties3,880
#185 /undefined3,877
#186 /.well-known/resource-that-should-not-exist-whose-status-code-should-not-be-2003,861
#187 /wp-admin/includes/index.php3,778
#188 /wiki3,776
#189 /loja/catalogo.php3,754
#190 /.env.bak3,747
#191 /contact3,701
#192 /blog3,689
#193 /al.php3,677
#194 /wp-admin/network/network.php3,665
#195 /administrator3,656
#196 /admin/admin.php3,651
#197 /moddofuns.php3,649
#198 /s.php3,645
#199 /adminfuns.php3,636
#200 /shell.php3,634
#201 /.well-known/acme-challenge/mariju.php3,630
#202 /pinfo.php3,613
#203 /themes/zMousse/otuz1.php3,606
#204 /wp-content/themes/admin.php3,602
#205 /feed/mnpodcast3,602
#206 /acessorios-cameras/capa-de-silicone3,590
#207 /fox.php3,589
#208 /php8.php3,566
#209 /doiconvs.php3,536
#210 /.git/HEAD3,531
#211 /wp-content/admin.php3,509
#212 /admin/.env3,508
#213 /wp-content3,494
#214 /.well-known/acme-challenge/makeasmtp.php3,473
#215 /07550e183,465
#216 /function.php3,457
#217 /.aws/credentials3,449
#218 /function/function.php3,441
#219 /c/linha-glass/robo-aspirador3,421
#220 /backend/.env3,420
#221 /wp-includes/blocks/about.php3,413
#222 /wp-content/themes/about.php3,413
#223 /wp-admin/css/qPyYcxpHKCu.php3,410
#224 /images/class-config.php3,397
#225 /Form3,397
#226 /wp-admin/js/about.php3,383
#227 /wp-l0gin.php3,375
#228 /wp-includes/wp-class.php3,373
#229 /install.php3,366
#230 /.env.example3,353
#231 /wp-admin/profile.php3,332
#232 /x.php3,327
#233 /api/v2/freights/3163,318
#234 /wp-admin/plugins.php3,306
#235 /10.php3,304
#236 /files3,296
#237 /.well-known/classwithtostring.php3,290
#238 /infos.php3,285
#239 /wp-admin/wp-login.php3,279
#240 /.env.local3,279
#241 /wp-admin/mah.php3,268
#242 /fix.php3,253
#243 /wp-admin/edit.php3,251
#244 /content.php3,249
#245 /file15.php3,246
#246 /file3.php3,229
#247 /a.php3,216
#248 /new.php3,210
#249 /13.php3,206
#250 /gel4y.php3,205
#251 /sdk3,203
#252 /wp-admin.php3,197
#253 /2020/wp-includes/wlwmanifest.xml3,179
#254 /error.php3,146
#255 /file9.php3,137
#256 /evox/about3,137
#257 /wp-admin/chosen.php3,118
#258 /epinyins.php3,118
#259 /app/.env3,117
#260 /mah.php3,114
#261 /.well-known/acme-challenge/doc.php3,112
#262 /wp-admin/css/colors/ectoplasm/about.php3,112
#263 /.env.prod3,112
#264 /wp-admin/admin-ajax.php3,108
#265 /wp-admin/css/colors/blue/about.php3,107
#266 /pages.php3,099
#267 /api/config.env3,097
#268 /laravel/.env3,095
#269 /default.php3,083
#270 /0x.php3,080
#271 /pb3,069
#272 /inc.php3,055
#273 /wp-aa.php3,049
#274 /core/.env3,044
#275 /categoria-produto/aneis/feminino3,041
#276 /contrato/wap/crons/enviar-email.php3,040
#277 /api/sessions3,039
#278 /wp-admin/install.php3,033
#279 /ms-edit.php3,031
#280 /y.php3,030
#281 /wp-sitemap.xml3,030
#282 /wp-includes/about.php3,024
#283 /item.php3,004
#284 /wp-signin.php3,001
#285 /sts.php2,993
#286 /api/shared/config.env2,989
#287 /dev/.env2,983
#288 /setup.php2,963
#289 /NewFile.php2,961
#290 /cdn-cgi/rum2,952
#291 /bugz.php2,933
#292 /pagamento/mercadopago/ipn.php2,930
#293 /wp-admin/wp-admins.php2,913
#294 /assets/images/doc.php2,913
#295 /wp-admin/js2,904
#296 /ar.php2,902
#297 /wp-content/uploads/de_fb_uploads/b.php2,897
#298 /robots.php2,892
#299 /wp-trackback.php2,891
#300 /12.php2,883
#301 /wp-admin/wp.php2,874
#302 /b.php2,870
#303 /pp.php2,862
#304 /wp-content/plugins/WordPressCore/include.php2,859
#305 /wp-includes/ID3/index.php2,855
#306 /h.php2,851
#307 /wp-admin/css/colors/light/wp-login.php2,829
#308 /gelay.php2,822
#309 /public/.env2,815
#310 /ini.php2,808
#311 /wp-admin/js/wp-conflg.php2,808
#312 /wp-admin/css/colors/blue2,805
#313 /file7.php2,804
#314 /api/config/config.yml2,787
#315 /wp-content/plugins/pwnd/as.php2,779
#316 /_phpinfo.php2,772
#317 /api/v2/customers/login2,767
#318 /wp-conflg.php2,749
#319 /file6.php2,747
#320 /wp-content/plugins/autoload_classmap.php2,739
#321 /wp-includes/html-api/about.php2,737
#322 /test1.php2,731
#323 /composer.php2,727
#324 /version2,726
#325 /application/.env2,725
#326 /form.html2,709
#327 /ova.php2,708
#328 /wp-admin/admin.php2,700
#329 /wp-admin/includes/colour.php2,669
#330 /wp-admin/includes/header.php2,660
#331 /images/admin.php2,653
#332 /blog/fw.php2,645
#333 /upl.php2,638
#334 /g/collect2,631
#335 /t42,629
#336 /systembc/password.php2,628
#337 /password.php2,626
#338 /geoip2,626
#339 /null2,618
#340 /not_found2,618
#341 /.AWS_/credentials2,617
#342 /v.php2,594
#343 /servicos2,588
#344 /api/v2/products/3862,586
#345 /.git/index2,584
#346 /rt.php2,581
#347 /api/objects/codes.php.save2,575
#348 /member-signup2,573
#349 /config/aws.yml2,573
#350 /memberfuns.php2,568
#351 /wp-admin/css/colors/blue/atomlib.php2,561
#352 /wp-includes/ALFA_DATA/alfacgiapi/perl.alfa2,550
#353 /wp-admin/includes/wp-conflg.php2,546
#354 /.aws/config2,543
#355 /.well-known/radio.php2,535
#356 /privacidade2,535
#357 /loja/busca.php2,530
#358 /moon.php2,523
#359 /auth.php2,519
#360 /local/.env2,514
#361 /assets/images/accesson.php2,511
#362 /ms-themes.php2,510
#363 /wp-content/languages/autoload_classmap.php2,489
#364 /mini2,486
#365 /admin/controller/extension/extension2,484
#366 /web/.env2,480
#367 /file8.php2,467
#368 /wp-content/plugins/about.php2,463
#369 /ws.php2,463
#370 /we.php2,460
#371 /projetos2,458
#372 /wp-content/classwithtostring.php2,453
#373 /.bod/.ll/ss.php2,447
#374 /options-writing.php2,445
#375 /options-reading.php2,444
#376 /projetos/italiaetal2,440
#377 /wp-admin/autoload_classmap.php2,440
#378 /apps/.env2,434
#379 /wp-content/uploads/json.php2,428
#380 /xx.php2,426
#381 /search2,418
#382 /plugins.php2,417
#383 /site/.env2,416
#384 /aws.yml2,414
#385 /index.bak.php2,405
#386 /depoimentos2,405
#387 /ab2g2,403
#388 /13k.php2,401
#389 /ola-mundo2,401
#390 /ab2h2,400
#391 /wp-logs.php2,395
#392 /new/.env2,395
#393 /wp-wso.php2,393
#394 /en_en/eventi/(2,384
#395 /alive.php2,378
#396 /teorema5052,377
#397 /gdftps.php2,376
#398 /2018/wp-includes/wlwmanifest.xml2,376
#399 /.alf.php2,372
#400 /www/.env2,365
#401 /prod/.env2,363
#402 /wp-setting.php2,359
#403 /docker/.env2,359
#404 /87.php2,356
#405 /wp-content/plugins/ioxi/ioxi/dropdown.php2,355
#406 /wp-content/plugins/up/main.php2,353
#407 /groups%22%222,353
#408 /wp_wrong_datlib.php2,352
#409 /settings.py2,351
#410 /log.php2,336
#411 /.env.old2,327
#412 /cron/.env2,327
#413 /options-general.php2,326
#414 /wp-content/plugin.php2,320
#415 /wp-content/x.php2,318
#416 /wp-content/1.php2,316
#417 /crm/.env2,314
#418 /.env.production.local2,305
#419 /wp-content/wp.php2,303
#420 /.well-known/about/function.php2,299
#421 /.env.stage2,296
#422 /main/.env2,294
#423 /conf/.env2,290
#424 /dashboard/phpinfo.php2,285
#425 /mail/.env2,271
#426 /wp-config.php.bak2,261
#427 /env/.env2,261
#428 /site2,249
#429 /aws-secret.yaml2,248
#430 /jp.php2,239
#431 /server-info2,229
#432 /.well-known/index.php2,223
#433 /lara/info.php2,222
#434 /api/v2/categories/862,220
#435 /.vscode/.env2,218
#436 /.well-known/acme-challenge/index.php2,214
#437 /server-info.php2,209
#438 /wp-content/click.php2,207
#439 /_profiler/phpinfo/phpinfo.php2,206
#440 /js/.env2,205
#441 /awstats/.env2,204
#442 /login.php2,202
#443 /lara/phpinfo.php2,201
#444 /images2,201
#445 /xampp/phpinfo.php2,200
#446 /wp-includes/widgets/autoload_classmap.php2,199
#447 /wp-includes/fonts/autoload_classmap.php2,199
#448 /wp-includes/IXR/chosen.php2,198
#449 /pesca/login/index.php2,198
#450 /development/.env2,196
#451 /contact-us2,196
#452 /wp-comments.php2,195
#453 /files/index.php2,194
#454 /mailer/.env2,193
#455 /.travis.yml2,182
#456 /nginx/.env2,177
#457 /wp-includes/style-engine/autoload_classmap.php2,176
#458 /alfanew.php2,175
#459 /env.backup2,169
#460 /portal/.env2,167
#461 /apiundefined2,163
#462 /_profiler/phpinfo/info.php2,162
#463 /website/.env2,160
#464 /new/.env.staging2,160
#465 /en/assets/images/logos/HTB.JPG2,159
#466 /app/config/parameters.yml2,157
#467 /node_modules/.env2,157
#468 /wp-error.php2,152
#469 /new/.env.local2,151
#470 /wp-includes/wp_class_datlib.php2,149
#471 /wp-includes/css/autoload_classmap.php2,143
#472 /admin/config2,143
#473 /sanitas-bk/wp-json/metform/v1/forms/views/6542,140
#474 /storage/logs/laravel.log2,140
#475 /cms2,135
#476 /.env_sample2,134
#477 /i.php2,130
#478 /wp-includes/PHPMailer/file.php2,129
#479 /uploads2,128
#480 /laravel/info.php2,127
#481 /docker/app/.env2,123
#482 /laravel/core/.env2,123
#483 /wp-includes/js/tinymce/langs/about.php2,122
#484 /application.properties2,121
#485 /wp-config2,121
#486 /post.php2,108
#487 /wp-admin/includes/about.php2,107
#488 /dynip/f282640c2,106
#489 /wp-includes/pomo/about.php2,099
#490 /secured/phpinfo.php2,098
#491 /config.env2,092
#492 /kyc/.env2,089
#493 /2.php2,088
#494 /wp-includes/certificates/chosen.php2,086
#495 /new/.env.production2,085
#496 /.well-known/gecko-litespeed.php2,082
#497 /wp-content/uploads/chosen.php2,075
#498 /wp-includes/SimplePie/chosen.php2,073
#499 /xampp/.env2,072
#500 /geju.php2,070


Data was last updated on: Sep 17, 2025



Logging Research

We love logs. In this section we will share some of the data we are parsing from our logs and honeypots we have live.

Trunc Logging

Logging for fun and a good night of sleep.

  • Real time search
  • Google simple
  • Cheap
  • Just works
  • PCI compliance
Trunc Research

Latest log-based threat analysis added.

Contact us!

Do you have an idea for a research that is not here? See something wrong? Contact us at support@noc.org

Tired of price gouging
  • Clear pricing
  • No need to guess
  • Real people
  • Real logging

Simple, Affordable, Log Management and Analysis.

14 days free trial. No credit card required.