Web logs 404 analysis - all time
Dec 15, 2025
Automatically updated daily

Checking for 404 errors in your logs can reveal more than just broken links, it can also expose files and URLs that attackers are actively scanning for. To track this behavior, we set up hundreds of honeypots and analyzed live web traffic data, giving us insight into which files and URLs are being targeted across the internet.


The table bellow list the top URLs being scanned all time and is updated daily. Most of the data contain WordPress specific URLs, certain plugins and config files that attackers can use.


Rank Scanned URL Counter
#1 /wp-login.php582,384
#2 /autodiscover/autodiscover.xml270,767
#3 /xmlrpc.php141,218
#4 /.env100,155
#5 /index.php95,643
#6 /.well-known/traffic-advice92,135
#7 /sitemap.xml83,518
#8 /201257,492
#9 /wp-json/oembed/1.0/embed44,588
#10 /40444,201
#11 /.git/config41,206
#12 /module/ngmercadolivre/notificacao35,773
#13 /info.php32,485
#14 /manager/html30,575
#15 /login29,366
#16 /file.php28,938
#17 /admin.php28,433
#18 /api/v2/auth28,144
#19 /chosen.php25,616
#20 /en/AutoDiscover/autodiscover.xml25,137
#21 /about.php25,072
#22 /wp-cron.php24,194
#23 /wordpress23,256
#24 /wp-content/plugins/hellopress/wp_filemanager.php22,079
#25 /backup21,618
#26 /wp-admin20,575
#27 /wp20,123
#28 /api/catalog_system/pub/products/search18,923
#29 /.well-known/nodeinfo17,608
#30 /old17,446
#31 /alfa.php17,265
#32 /wp-content/plugins/fix/up.php17,166
#33 /_profiler/phpinfo17,156
#34 /404testpage4525d2fdc16,497
#35 /wp-includes/wlwmanifest.xml16,223
#36 /bk16,197
#37 /api/v2/marketplace/sellers/376/products/status-batch16,186
#38 /phpinfo16,100
#39 /api/v2/marketplace/sellers/376/products/stock-batch16,088
#40 /api/v2/marketplace/sellers/376/products/price-batch16,073
#41 /bc16,072
#42 /en/autodiscover/autodiscover.xml16,024
#43 /atomlib.php15,906
#44 /1.php15,784
#45 /.well-known/acme-challenge/about.php15,709
#46 /wp.php15,562
#47 /new15,554
#48 /classwithtostring.php15,290
#49 /admin15,267
#50 /autoload_classmap.php15,238
#51 /main15,213
#52 /goods.php14,967
#53 /aa.php14,810
#54 /api/.env14,774
#55 /rest/V1/store/storeViews14,751
#56 /test.php14,178
#57 /simple.php14,141
#58 /lock360.php13,944
#59 /ioxi-o.php13,922
#60 /flower.php13,894
#61 /api/v2/categories/6513,887
#62 /file2.php13,747
#63 /web/wp-includes/wlwmanifest.xml13,677
#64 /wordpress/wp-includes/wlwmanifest.xml13,544
#65 /wp/wp-includes/wlwmanifest.xml13,319
#66 /admin/config.php13,294
#67 /-/-/-/-/-/-/-/-/-/-13,048
#68 /app12,964
#69 /blog/wp-includes/wlwmanifest.xml12,895
#70 /2019/wp-includes/wlwmanifest.xml12,768
#71 /debug/default/view12,721
#72 /shop/wp-includes/wlwmanifest.xml12,682
#73 /shop12,661
#74 /app_dev.php/_profiler/phpinfo12,651
#75 /backend/.env12,537
#76 /edit.php12,531
#77 /.well-known/passkey-endpoints12,325
#78 /admin/.env12,303
#79 /makeasmtp.php12,172
#80 /v2/_catalog12,125
#81 /test12,086
#82 /pagamento/mercadopago/ipn.php12,048
#83 /website/wp-includes/wlwmanifest.xml12,018
#84 /cong.php11,998
#85 /cdn-cgi/rum11,977
#86 /AutoDiscover/autodiscover.xml11,906
#87 /server-status11,857
#88 /news/wp-includes/wlwmanifest.xml11,853
#89 /web_api/auth11,838
#90 /.env.example11,775
#91 /feed11,649
#92 /style.php11,504
#93 /contrato/wap/crons/enviar-email.php11,300
#94 /api11,178
#95 /telescope/requests11,145
#96 /acessorios-cameras10,809
#97 /.well-known/apple-app-site-association10,782
#98 /akc.php10,642
#99 /autoload_classmap/function.php10,459
#100 /radio.php10,343
#101 /buy.php10,298
#102 /api/v2/categories/6410,248
#103 /asasx.php10,203
#104 /wp-plain.php10,154
#105 /inputs.php10,120
#106 /api/graphql10,075
#107 /login.action9,927
#108 /wp-admin/css9,927
#109 /home9,916
#110 /css.php9,789
#111 /phpinfo.php9,713
#112 /about9,646
#113 /dropdown.php9,641
#114 /k.php9,518
#115 /as.php9,452
#116 /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application9,397
#117 /w.php9,334
#118 /akcc.php9,304
#119 /user/login9,293
#120 /abcd.php9,169
#121 /server9,158
#122 /@vite/env9,121
#123 /_all_dbs9,120
#124 /actuator/env9,045
#125 /goat.php8,903
#126 /api/v2/customers/login8,884
#127 /api/sessions8,750
#128 /loja/login_layout.php8,708
#129 /cgi-bin/luci/;stok=/locale8,701
#130 /wp-json/sfwd-assignment/18,681
#131 /404.php8,678
#132 /HNAP18,521
#133 /wordpress/wp-admin/setup-config.php8,470
#134 /lv.php8,433
#135 /files8,302
#136 /gecko.php8,261
#137 /loja/catalogo.php8,148
#138 /config.php8,061
#139 /wp-sitemap.xml8,013
#140 /07550e188,000
#141 /wp-content/plugins/woocommerce/includes/gateways/locks.php7,910
#142 /wp-admin/classwithtostring.php7,779
#143 /wp-admin/images/moon.php7,756
#144 /manager.php7,697
#145 /.well-known/acme-challenge/cloud.php7,656
#146 /contato7,615
#147 /appWP/lab/wp-admin/css/colors/blue/blue.php7,599
#148 /wsa.php7,566
#149 /bless.php7,560
#150 /wp-admin/setup-config.php7,518
#151 /nc4.php7,501
#152 /wiki7,470
#153 /wp-content/index.php7,440
#154 /administrator7,418
#155 /php.php7,414
#156 /wp-content/wp-conflg.php7,377
#157 /f35.php7,375
#158 /wp-content/themes/seotheme/db.php7,347
#159 /admin/index.php7,302
#160 /tinyfilemanager.php7,290
#161 /gmo.php7,289
#162 /403.php7,279
#163 /mar.php7,235
#164 /g/collect7,194
#165 /gg.php7,180
#166 /saiga.php7,127
#167 /themes.php7,119
#168 /adminfuns.php7,107
#169 /api/v3/community7,103
#170 /users.php7,084
#171 /s/1313e2236313e20373e2538313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties7,033
#172 /zwso.php7,000
#173 /mm.php6,970
#174 /doc.php6,870
#175 /content.php6,840
#176 /cms6,807
#177 /index/function.php6,804
#178 /wp-admin/index.php6,802
#179 /system_log.php6,777
#180 /filemanager.php6,763
#181 /wp-content/autoload_classmap.php6,723
#182 /blog6,719
#183 /2018/wp-includes/wlwmanifest.xml6,624
#184 /.env.bak6,555
#185 /images6,524
#186 /shell.php6,523
#187 /pb6,516
#188 /images/images/cache.php6,509
#189 /feed/mnpodcast6,481
#190 /wp-admin/wp-conflg.php6,443
#191 /boaform/admin/formLogin6,412
#192 /wp-admin/css/colors/blue/index.php6,391
#193 /wp-content/video6,389
#194 /new.php6,348
#195 /wp-api.php6,339
#196 /mah.php6,338
#197 /g.php6,326
#198 /.aws/credentials6,308
#199 /2020/wp-includes/wlwmanifest.xml6,298
#200 /cc.php6,273
#201 /api/v2/freights/3166,272
#202 /moon.php6,245
#203 /wp-admin/js/autoload_classmap.php6,240
#204 /wp-admin/js/index.php6,217
#205 /wp-includes/fonts/admin.php6,208
#206 /rest/V1/inventory/source-items6,203
#207 /class.php6,188
#208 /wp-setup.php6,182
#209 /bolt.php6,161
#210 /php_info.php6,154
#211 /wp-content/themes/about.php6,152
#212 /wso.php6,117
#213 /api/shared/config/config.env6,095
#214 /null6,092
#215 /file17.php6,051
#216 /laravel/.env6,021
#217 /[object%20Object]6,007
#218 /mini.php5,951
#219 /wp-content/admin.php5,923
#220 /.well-known/acme-challenge/xmrlpc.php5,906
#221 /contact5,871
#222 /app/.env5,834
#223 /foq.php5,827
#224 /loja/busca.php5,827
#225 /sdk5,785
#226 /Form5,778
#227 /install.php5,767
#228 /.env.local5,761
#229 /file5.php5,738
#230 /wp-admin/maint/about.php5,734
#231 /evox/about5,715
#232 /core/.env5,661
#233 /assets/images/accesson.php5,658
#234 /admin/function.php5,610
#235 /wp-includes/IXR/autoload_classmap.php5,561
#236 /wp-includes/fonts/index.php5,555
#237 /wp-content/themes/admin.php5,534
#238 /wp-content/style.php5,500
#239 /wp-content/about.php5,496
#240 /wp-json/sfwd-lessons/15,437
#241 /sitemap_index.xml5,383
#242 /wp-content5,378
#243 /wp-json/sfwd-topic/15,302
#244 /undefined5,290
#245 /default.php5,283
#246 /item.php5,252
#247 /wp-admin/edit-tags.php5,251
#248 /loja/cartService.php5,238
#249 /byp.php5,237
#250 /uploads5,225
#251 /sk_es/vozik5,216
#252 /wp-content/plugins/wpterm.php5,198
#253 /wp-content/plugins/WordPressCore/include.php5,187
#254 /comment.php5,175
#255 /pinfo.php5,147
#256 /about/function.php5,126
#257 /admin/controller/extension/extension5,091
#258 /.git/HEAD5,052
#259 /upload/banner5,023
#260 /.env.prod4,999
#261 /function/function.php4,987
#262 /password.php4,975
#263 /a.php4,952
#264 /wp-json/custom/v14,922
#265 /apps/.env4,871
#266 /m.php4,861
#267 /ty.php4,825
#268 /api/v2/marketplace/sellers/615/products/queue4,810
#269 /index.html4,803
#270 /files.php4,794
#271 /form.html4,769
#272 /wp-editor.php4,754
#273 /wp-admin/admin-ajax.php4,751
#274 /ahax.php4,741
#275 /pesca/login/index.php4,716
#276 /.well-known/change-password4,712
#277 /graphql4,687
#278 /error.php4,686
#279 /api/v2/products/3864,686
#280 /we.php4,674
#281 /web/.env4,668
#282 /.well-known/web-identity4,661
#283 /upl.php4,660
#284 /systembc/password.php4,632
#285 /.git/index4,629
#286 /t44,625
#287 /geoip4,623
#288 /.well-known/webauthn4,618
#289 /.well-known/resource-that-should-not-exist-whose-status-code-should-not-be-2004,616
#290 /wp1/wp-includes/wlwmanifest.xml4,578
#291 /public/.env4,577
#292 /sites/default/files4,541
#293 /wp-admin/includes/index.php4,529
#294 /s.php4,526
#295 /13.php4,501
#296 /gifclass.php4,496
#297 /x.php4,484
#298 /sitemap.php4,458
#299 /222.php4,442
#300 /version4,441
#301 /site4,430
#302 /new/.env4,417
#303 /tytyd.php4,414
#304 /wp-admin/style.php4,402
#305 /dev/.env4,377
#306 /wp-content/plugins/pwnd/pwnd.php4,376
#307 /SistemaEAD_CPREM/login/index.php4,373
#308 /ws.php4,367
#309 /wp-admin/profile.php4,367
#310 /wp-admin/js4,352
#311 /NewFile.php4,348
#312 /wp-admin/js/widgets/cloud.php4,347
#313 /admin/admin.php4,344
#314 /xmrlpc.php4,342
#315 /fox.php4,339
#316 /ar.php4,326
#317 /.well-known/acme-challenge/mariju.php4,319
#318 /wordpress/wp-login.php4,319
#319 /ab2g4,313
#320 /ab2h4,311
#321 /wp-admin/file.php4,284
#322 /alive.php4,278
#323 /teorema5054,271
#324 /info4,258
#325 /web4,239
#326 /wp-admin/install.php4,224
#327 /wp-admin/plugins.php4,219
#328 /wp-admin.php4,208
#329 /wp-trackback.php4,197
#330 /wp-admin/edit.php4,164
#331 /wp-content/themes/style.php4,161
#332 /i.php4,143
#333 /wp-json/sfwd-courses4,142
#334 /wp-admin/js/about.php4,134
#335 /10.php4,128
#336 /al.php4,115
#337 /backend4,113
#338 /file15.php4,099
#339 /wp-admin/includes/colour.php4,094
#340 /portal/.env4,067
#341 /wp-admin/css/colors/blue4,065
#342 /api/v2/marketplace/sellers/655/products/queue4,030
#343 /sts.php3,997
#344 /file9.php3,973
#345 /0x.php3,971
#346 /wp-content/plugins/pwnd/as.php3,960
#347 /wp-signin.php3,950
#348 /application/.env3,942
#349 /elp.php3,927
#350 /infos.php3,926
#351 /dashboard3,903
#352 /wp-admin/css/colors/blue/atomlib.php3,882
#353 /wp-admin/wp-admins.php3,879
#354 /themes/zMousse/otuz1.php3,876
#355 /api/v2/marketplace/sellers/376/products/queue3,871
#356 /aws.yml3,858
#357 /api/v2/brands/47183,823
#358 /fix.php3,815
#359 /num.php3,795
#360 /ini.php3,782
#361 /groups%22%223,782
#362 /php8.php3,772
#363 /function.php3,757
#364 /config/aws.yml3,756
#365 /pp.php3,756
#366 /panel3,750
#367 /wp-includes/blocks/about.php3,750
#368 /fr3,748
#369 /wp-admin/network/network.php3,738
#370 /member-signup3,731
#371 /api/config.env3,730
#372 /wp-admin/css/about.php3,718
#373 /moddofuns.php3,714
#374 /www/.env3,707
#375 /wp-admin/wp-login.php3,706
#376 /cgi-bin3,700
#377 /images/class-config.php3,699
#378 /wp-conflg.php3,694
#379 /2.php3,680
#380 /wp-l0gin.php3,679
#381 /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php3,678
#382 /docker/.env3,667
#383 /ola-mundo3,666
#384 /_phpinfo.php3,655
#385 /wp-blog.php3,653
#386 /js/.env3,652
#387 /api/shared/config.env3,651
#388 /crm/.env3,644
#389 /gel4y.php3,638
#390 /wp-admin/post-new.php3,638
#391 /contact-us3,629
#392 /wp-content/plugins/simple-ajax-chat/includes/sac-check-user.php3,616
#393 /login.php3,615
#394 /env/.env3,605
#395 /ee.php3,601
#396 /acessorios-cameras/capa-de-silicone3,590
#397 /xx.php3,589
#398 /cron/.env3,586
#399 /file3.php3,572
#400 /cursogratuito/ola-mundo3,571
#401 /wp-includes/wp-class.php3,570
#402 /comment-subscriptions3,542
#403 /app/config/parameters.yml3,540
#404 /CLA.php3,540
#405 /doiconvs.php3,536
#406 /.well-known3,526
#407 /item/Caique-Brudden-Explorer-Fishing-Up-.html3,520
#408 /api/v2/products/55183,517
#409 /epinyins.php3,506
#410 /test1.php3,495
#411 /en/assets/images/logos/HTB.JPG3,487
#412 /dynip/f282640c3,486
#413 /.well-known/acme-challenge/makeasmtp.php3,483
#414 /mah/function.php3,475
#415 /wp-admin/css/colors/ectoplasm/about.php3,474
#416 /file7.php3,457
#417 /fm.php3,455
#418 /wp-content/plugins/admin.php3,443
#419 /loja/carrinho.php3,440
#420 /simular3,436
#421 /api/v2/products/16593714623,434
#422 /v.php3,431
#423 /wp-json/oembed3,427
#424 /c/linha-glass/robo-aspirador3,421
#425 /wp-json/wp3,420
#426 /api/v2/products/16593720223,418
#427 /api/v2/products/16593695923,414
#428 /wp-admin/css/qPyYcxpHKCu.php3,410
#429 /cabelo/marcas-de-salao/wella-professionals/wella-professionals-invigo-color-brilliance-2-produtos3,408
#430 /api/v2/products/16593706903,407
#431 /12.php3,405
#432 /api/v2/products/16593711943,404
#433 /api/v2/products/16593701433,399
#434 /local/.env3,398
#435 /api/v2/products/16593705403,398
#436 /wp-json/sfwd-lessons3,394
#437 /wp-admin/js/wp-conflg.php3,394
#438 /api/v2/products/16593718843,394
#439 /api/v2/products/16593720423,394
#440 /api/v2/products/16593690383,392
#441 /.vscode/.env3,390
#442 /api/v2/products/16593703153,389
#443 /api/v2/products/16593710293,389
#444 /api/v2/products/16593698633,384
#445 /api/v2/products/16593709403,383
#446 /api/v2/products/16593719503,382
#447 /inc.php3,379
#448 /api/v2/products/16593693183,379
#449 /api/v2/products/16593706493,378
#450 /api/v2/products/16593694853,378
#451 /a2.php3,377
#452 /wp-admin/css/colors/blue/about.php3,377
#453 /api/v2/products/16593712173,375
#454 /api/v2/products/16593705393,375
#455 /api/v2/products/16593714893,373
#456 /wp-aa.php3,372
#457 /.aws/config3,371
#458 /api/v2/products/16593699413,368
#459 /alfanew.php3,365
#460 /wp-json/sfwd-courses/13,363
#461 /y.php3,363
#462 /.well-known/classwithtostring.php3,362
#463 /gelay.php3,361
#464 /api/v2/products/16593697653,361
#465 /api/v2/products/16593693663,358
#466 /api/v2/products/16593689753,354
#467 /api/v2/products/16593717303,350
#468 /wp-admin/mah.php3,348
#469 /api/v2/batch/11103,341
#470 /b.php3,338
#471 /not_found3,330
#472 /site/.env3,298
#473 /api/config/config.yml3,292
#474 /mini3,290
#475 /wp-good.php3,282
#476 /settings.py3,269
#477 /wp-admin/chosen.php3,255
#478 /wp-json/sfwd-topic3,254
#479 /mail.php3,245
#480 /test/wp-includes/wlwmanifest.xml3,239
#481 /prod/.env3,236
#482 /.AWS_/credentials3,232
#483 /pages.php3,218
#484 /.env.old3,217
#485 /wp-includes/about.php3,216
#486 /wp-content/classwithtostring.php3,204
#487 /log.php3,201
#488 /tool/view/phpinfo.view.php3,189
#489 /api/v2/batch/11113,189
#490 /build.php3,176
#491 /rest/V1/orders3,176
#492 /api/v2/marketplace/sellers/376/products/batch3,175
#493 /.env.production.local3,171
#494 /post.php3,171
#495 /wp-content/plugins/about.php3,170
#496 /geju.php3,161
#497 /setup.php3,151
#498 /dashboard/phpinfo.php3,146
#499 /awstats/.env3,144
#500 /.env.stage3,142


Data was last updated on: Dec 15, 2025



Logging Research

We love logs. In this section we will share some of the data we are parsing from our logs and honeypots we have live.

Trunc Logging

Logging for fun and a good night of sleep.

  • Real time search
  • Google simple
  • Cheap
  • Just works
  • PCI compliance
Trunc Research

Latest log-based threat analysis added.

Contact us!

Do you have an idea for a research that is not here? See something wrong? Contact us at support@noc.org

Tired of price gouging
  • Clear pricing
  • No need to guess
  • Real people
  • Real logging

Simple, Affordable, Log Management and Analysis.

14 days free trial. No credit card required.