Web logs 404 analysis - all time
Jan 12, 2026
Automatically updated daily

Checking for 404 errors in your logs can reveal more than just broken links, it can also expose files and URLs that attackers are actively scanning for. To track this behavior, we set up hundreds of honeypots and analyzed live web traffic data, giving us insight into which files and URLs are being targeted across the internet.


The table bellow list the top URLs being scanned all time and is updated daily. Most of the data contain WordPress specific URLs, certain plugins and config files that attackers can use.


Rank Scanned URL Counter
#1 /wp-login.php587,794
#2 /autodiscover/autodiscover.xml276,632
#3 /xmlrpc.php142,145
#4 /.env100,746
#5 /index.php96,563
#6 /.well-known/traffic-advice95,030
#7 /sitemap.xml84,178
#8 /201257,492
#9 /40445,539
#10 /wp-json/oembed/1.0/embed45,159
#11 /.git/config41,757
#12 /api/v2/auth41,539
#13 /module/ngmercadolivre/notificacao35,862
#14 /info.php34,099
#15 /file.php30,827
#16 /manager/html30,575
#17 /admin.php30,279
#18 /login29,517
#19 /about.php26,539
#20 /chosen.php26,057
#21 /en/AutoDiscover/autodiscover.xml25,355
#22 /wp-cron.php24,651
#23 /wordpress23,415
#24 /wp-content/plugins/hellopress/wp_filemanager.php22,193
#25 /backup21,759
#26 /wp-admin20,898
#27 /wp20,269
#28 /api/catalog_system/pub/products/search18,944
#29 /alfa.php18,142
#30 /.well-known/nodeinfo17,614
#31 /old17,586
#32 /wp-content/plugins/fix/up.php17,255
#33 /_profiler/phpinfo17,214
#34 /wp.php16,898
#35 /classwithtostring.php16,767
#36 /404testpage4525d2fdc16,601
#37 /wp-includes/wlwmanifest.xml16,411
#38 /bk16,276
#39 /phpinfo16,199
#40 /api/v2/marketplace/sellers/376/products/status-batch16,186
#41 /en/autodiscover/autodiscover.xml16,169
#42 /1.php16,125
#43 /api/v2/marketplace/sellers/376/products/stock-batch16,088
#44 /api/v2/marketplace/sellers/376/products/price-batch16,073
#45 /goods.php16,073
#46 /bc16,072
#47 /aa.php15,991
#48 /atomlib.php15,969
#49 /ioxi-o.php15,951
#50 /.well-known/acme-challenge/about.php15,752
#51 /new15,681
#52 /autoload_classmap.php15,630
#53 /admin15,418
#54 /main15,213
#55 /api/.env14,977
#56 /rest/V1/store/storeViews14,860
#57 /simple.php14,537
#58 /test.php14,413
#59 /flower.php14,020
#60 /lock360.php14,006
#61 /api/v2/categories/6513,887
#62 /web/wp-includes/wlwmanifest.xml13,835
#63 /file2.php13,830
#64 /wordpress/wp-includes/wlwmanifest.xml13,700
#65 /edit.php13,686
#66 /.well-known/passkey-endpoints13,511
#67 /wp/wp-includes/wlwmanifest.xml13,473
#68 /admin/config.php13,307
#69 /-/-/-/-/-/-/-/-/-/-13,148
#70 /blog/wp-includes/wlwmanifest.xml13,051
#71 /app13,009
#72 /shop13,008
#73 /2019/wp-includes/wlwmanifest.xml12,912
#74 /shop/wp-includes/wlwmanifest.xml12,824
#75 /app_dev.php/_profiler/phpinfo12,797
#76 /debug/default/view12,743
#77 /backend/.env12,714
#78 /admin/.env12,466
#79 /web_api/auth12,403
#80 /cong.php12,348
#81 /cdn-cgi/rum12,332
#82 /makeasmtp.php12,205
#83 /AutoDiscover/autodiscover.xml12,168
#84 /website/wp-includes/wlwmanifest.xml12,160
#85 /v2/_catalog12,153
#86 /pagamento/mercadopago/ipn.php12,130
#87 /test12,110
#88 /news/wp-includes/wlwmanifest.xml11,995
#89 /.env.example11,944
#90 /server-status11,911
#91 /feed11,819
#92 /style.php11,777
#93 /buy.php11,734
#94 /contrato/wap/crons/enviar-email.php11,581
#95 /api11,294
#96 /telescope/requests11,199
#97 /abcd.php11,015
#98 /radio.php10,997
#99 /autoload_classmap/function.php10,942
#100 /akc.php10,938
#101 /inputs.php10,842
#102 /asasx.php10,825
#103 /acessorios-cameras10,809
#104 /.well-known/apple-app-site-association10,799
#105 /akcc.php10,760
#106 /api/v2/categories/6410,248
#107 /wp-admin/css10,229
#108 /wp-plain.php10,207
#109 /dropdown.php10,126
#110 /api/graphql10,078
#111 /k.php9,955
#112 /login.action9,934
#113 /home9,921
#114 /css.php9,898
#115 /phpinfo.php9,873
#116 /as.php9,695
#117 /about9,663
#118 /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application9,408
#119 /w.php9,352
#120 /user/login9,352
#121 /server9,165
#122 /@vite/env9,126
#123 /_all_dbs9,126
#124 /api/sessions9,092
#125 /actuator/env9,066
#126 /saiga.php9,014
#127 /api/v2/customers/login8,994
#128 /bless.php8,973
#129 /404.php8,944
#130 /goat.php8,903
#131 /adminfuns.php8,846
#132 /loja/login_layout.php8,820
#133 /cgi-bin/luci/;stok=/locale8,702
#134 /wp-json/sfwd-assignment/18,681
#135 /HNAP18,630
#136 /wordpress/wp-admin/setup-config.php8,545
#137 /lv.php8,490
#138 /files8,452
#139 /gecko.php8,420
#140 /php.php8,318
#141 /loja/catalogo.php8,301
#142 /config.php8,246
#143 /wp-admin/classwithtostring.php8,088
#144 /wp-sitemap.xml8,022
#145 /07550e188,022
#146 /wp-content/plugins/woocommerce/includes/gateways/locks.php7,910
#147 /wp-content/index.php7,878
#148 /.well-known/acme-challenge/cloud.php7,869
#149 /appWP/lab/wp-admin/css/colors/blue/blue.php7,848
#150 /403.php7,833
#151 /manager.php7,798
#152 /themes.php7,780
#153 /wp-admin/images/moon.php7,756
#154 /bolt.php7,736
#155 /[object%20Object]7,690
#156 /administrator7,678
#157 /contato7,657
#158 /wsa.php7,599
#159 /wp-admin/setup-config.php7,597
#160 /nc4.php7,523
#161 /wiki7,477
#162 /f35.php7,439
#163 /wp-content/wp-conflg.php7,413
#164 /wp-content/themes/seotheme/db.php7,393
#165 /gg.php7,388
#166 /gmo.php7,343
#167 /admin/index.php7,326
#168 /index/function.php7,313
#169 /tinyfilemanager.php7,311
#170 /g/collect7,309
#171 /mar.php7,249
#172 /users.php7,125
#173 /api/v3/community7,103
#174 /zwso.php7,101
#175 /content.php7,055
#176 /s/1313e2236313e20373e2538313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties7,037
#177 /wp-admin/index.php6,987
#178 /mm.php6,977
#179 /wp-content/autoload_classmap.php6,944
#180 /doc.php6,930
#181 /images6,832
#182 /blog6,821
#183 /filemanager.php6,819
#184 /class.php6,819
#185 /null6,815
#186 /system_log.php6,810
#187 /cms6,807
#188 /images/images/cache.php6,734
#189 /shell.php6,732
#190 /2018/wp-includes/wlwmanifest.xml6,716
#191 /wp-content/admin.php6,668
#192 /pb6,637
#193 /.env.bak6,613
#194 /new.php6,607
#195 /wp-admin/js/index.php6,543
#196 /wp-admin/css/colors/blue/index.php6,532
#197 /wp-content/video6,523
#198 /feed/mnpodcast6,512
#199 /boaform/admin/formLogin6,478
#200 /wp-admin/wp-conflg.php6,466
#201 /wp-content/themes/about.php6,464
#202 /cc.php6,457
#203 /mah.php6,441
#204 /wp-admin/js/autoload_classmap.php6,426
#205 /install.php6,425
#206 /upload/banner6,398
#207 /wp-content/themes/admin.php6,392
#208 /g.php6,353
#209 /2020/wp-includes/wlwmanifest.xml6,348
#210 /.aws/credentials6,343
#211 /wp-api.php6,339
#212 /api/v2/freights/3166,328
#213 /wso.php6,295
#214 /moon.php6,282
#215 /wp-includes/fonts/admin.php6,235
#216 /rest/V1/inventory/source-items6,203
#217 /wp-json/mod/v1/check-site6,198
#218 /php_info.php6,190
#219 /wp-setup.php6,182
#220 /mini.php6,180
#221 /api/shared/config/config.env6,097
#222 /laravel/.env6,069
#223 /file17.php6,052
#224 /.well-known/acme-challenge/xmrlpc.php6,004
#225 /ahax.php5,959
#226 /app/.env5,917
#227 /loja/busca.php5,893
#228 /contact5,878
#229 /sdk5,867
#230 /foq.php5,827
#231 /admin/function.php5,807
#232 /.env.local5,804
#233 /evox/about5,797
#234 /wp-content/about.php5,788
#235 /wp-admin/maint/about.php5,787
#236 /Form5,778
#237 /file5.php5,768
#238 /222.php5,746
#239 /core/.env5,711
#240 /assets/images/accesson.php5,663
#241 /admin/controller/extension/extension5,590
#242 /wp-content/style.php5,587
#243 /wp-includes/fonts/index.php5,579
#244 /wp-includes/IXR/autoload_classmap.php5,561
#245 /sitemap_index.xml5,518
#246 /wp-content5,460
#247 /wp-editor.php5,458
#248 /wp-json/sfwd-lessons/15,437
#249 /xmrlpc.php5,387
#250 /uploads5,383
#251 /undefined5,349
#252 /item.php5,324
#253 /default.php5,321
#254 /about/function.php5,319
#255 /byp.php5,312
#256 /wp-json/sfwd-topic/15,302
#257 /loja/cartService.php5,289
#258 /wp-admin/edit-tags.php5,252
#259 /13.php5,246
#260 /sk_es/vozik5,216
#261 /wp-content/plugins/wpterm.php5,198
#262 /wp-content/plugins/WordPressCore/include.php5,188
#263 /comment.php5,183
#264 /function/function.php5,169
#265 /pinfo.php5,164
#266 /a.php5,152
#267 /s.php5,098
#268 /.git/HEAD5,063
#269 /.env.prod5,034
#270 /password.php5,030
#271 /files.php4,926
#272 /wp-json/custom/v14,922
#273 /m.php4,908
#274 /apps/.env4,892
#275 /ty.php4,825
#276 /form.html4,824
#277 /index.html4,817
#278 /api/v2/products/3864,811
#279 /api/v2/marketplace/sellers/615/products/queue4,810
#280 /pesca/login/index.php4,804
#281 /wp-admin/admin-ajax.php4,788
#282 /wp-good.php4,736
#283 /tytyd.php4,731
#284 /upl.php4,715
#285 /.well-known/change-password4,712
#286 /web/.env4,711
#287 /error.php4,692
#288 /graphql4,691
#289 /systembc/password.php4,687
#290 /we.php4,683
#291 /t44,680
#292 /geoip4,678
#293 /.well-known/web-identity4,661
#294 /sites/default/files4,655
#295 /wp1/wp-includes/wlwmanifest.xml4,640
#296 /.git/index4,629
#297 /.well-known/webauthn4,618
#298 /.well-known/resource-that-should-not-exist-whose-status-code-should-not-be-2004,616
#299 /wp-admin/includes/index.php4,607
#300 /x.php4,606
#301 /public/.env4,599
#302 /gifclass.php4,592
#303 /wp-admin/js4,559
#304 /sitemap.php4,510
#305 /wp-admin/style.php4,479
#306 /wp-content/plugins/pwnd/pwnd.php4,478
#307 /wp-content/plugins/admin.php4,475
#308 /SistemaEAD_CPREM/login/index.php4,473
#309 /NewFile.php4,457
#310 /version4,443
#311 /dev/.env4,437
#312 /new/.env4,436
#313 /comment-subscriptions4,431
#314 /site4,430
#315 /ws.php4,419
#316 /ar.php4,376
#317 /ab2g4,371
#318 /ab2h4,369
#319 /wp-admin.php4,369
#320 /wp-admin/profile.php4,367
#321 /wp-trackback.php4,361
#322 /wp-admin/js/widgets/cloud.php4,347
#323 /admin/admin.php4,344
#324 /info4,344
#325 /fox.php4,339
#326 /alive.php4,336
#327 /wordpress/wp-login.php4,335
#328 /teorema5054,329
#329 /.well-known/acme-challenge/mariju.php4,319
#330 /i.php4,309
#331 /0x.php4,299
#332 /wp-admin/file.php4,284
#333 /wp-conflg.php4,271
#334 /wp-admin/install.php4,262
#335 /web4,248
#336 /wp-content/themes/style.php4,243
#337 /wp-admin/plugins.php4,219
#338 /wp-admin/js/about.php4,185
#339 /wp-admin/includes/colour.php4,181
#340 /api/v2/marketplace/sellers/655/products/queue4,165
#341 /wp-admin/edit.php4,164
#342 /wp-admin/css/colors/blue4,154
#343 /wp-json/sfwd-courses4,142
#344 /10.php4,128
#345 /al.php4,117
#346 /backend4,113
#347 /wp-signin.php4,111
#348 /file15.php4,099
#349 /elp.php4,091
#350 /portal/.env4,085
#351 /fr4,026
#352 /sts.php4,013
#353 /api/v2/brands/47184,010
#354 /file9.php3,992
#355 /num.php3,991
#356 /wp-content/plugins/pwnd/as.php3,987
#357 /api/v2/products/16593714623,983
#358 /application/.env3,979
#359 /api/v2/products/16593720223,965
#360 /api/v2/products/16593706903,955
#361 /api/v2/products/16593720423,954
#362 /api/v2/products/16593701433,951
#363 /api/v2/products/16593705403,949
#364 /api/v2/products/16593711943,948
#365 /api/v2/products/16593695923,947
#366 /infos.php3,942
#367 /api/v2/products/16593710293,939
#368 /api/v2/products/16593690383,938
#369 /api/v2/products/16593718843,930
#370 /api/v2/products/16593703153,929
#371 /api/v2/products/16593706493,928
#372 /api/v2/products/16593719503,926
#373 /api/v2/products/16593694853,924
#374 /wp-blog.php3,923
#375 /api/v2/products/16593693183,921
#376 /api/v2/products/16593699413,918
#377 /wp-admin/wp-admins.php3,916
#378 /api/v2/products/16593712173,916
#379 /gelay.php3,916
#380 /dashboard3,912
#381 /api/v2/products/16593697653,911
#382 /api/v2/products/16593714893,909
#383 /api/v2/products/16593705393,907
#384 /wp-admin/css/colors/blue/atomlib.php3,903
#385 /api/v2/products/16593693663,900
#386 /api/v2/products/16593717303,893
#387 /api/v2/products/16593689753,881
#388 /themes/zMousse/otuz1.php3,876
#389 /api/v2/marketplace/sellers/376/products/queue3,871
#390 /2.php3,868
#391 /cgi-bin3,866
#392 /aws.yml3,863
#393 /groups%22%223,827
#394 /ini.php3,820
#395 /fix.php3,815
#396 /php8.php3,806
#397 /gel4y.php3,806
#398 /api/v2/products/16593709403,802
#399 /function.php3,775
#400 /wp-admin/css/about.php3,767
#401 /ee.php3,764
#402 /pp.php3,761
#403 /config/aws.yml3,760
#404 /wp-includes/blocks/about.php3,754
#405 /panel3,750
#406 /wp-admin/network/network.php3,738
#407 /api/config.env3,733
#408 /member-signup3,733
#409 /moddofuns.php3,714
#410 /images/class-config.php3,709
#411 /www/.env3,708
#412 /wp-admin/wp-login.php3,706
#413 /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php3,702
#414 /ola-mundo3,691
#415 /.well-known3,688
#416 /simular3,687
#417 /wp-l0gin.php3,682
#418 /docker/.env3,669
#419 /crm/.env3,665
#420 /mah/function.php3,665
#421 /js/.env3,663
#422 /_phpinfo.php3,657
#423 /api/shared/config.env3,654
#424 /xx.php3,651
#425 /fm.php3,647
#426 /wp-admin/post-new.php3,639
#427 /contact-us3,629
#428 /login.php3,623
#429 /wp-content/plugins/simple-ajax-chat/includes/sac-check-user.php3,616
#430 /env/.env3,607
#431 /acessorios-cameras/capa-de-silicone3,590
#432 /cron/.env3,587
#433 /cursogratuito/ola-mundo3,587
#434 /12.php3,584
#435 /wp-includes/wp-class.php3,581
#436 /file3.php3,575
#437 /item/Caique-Brudden-Explorer-Fishing-Up-.html3,556
#438 /app/config/parameters.yml3,545
#439 /CLA.php3,542
#440 /doiconvs.php3,536
#441 /en/assets/images/logos/HTB.JPG3,522
#442 /test1.php3,518
#443 /api/v2/products/55183,517
#444 /epinyins.php3,506
#445 /wp-content/classwithtostring.php3,488
#446 /dynip/f282640c3,486
#447 /.well-known/acme-challenge/makeasmtp.php3,483
#448 /loja/carrinho.php3,478
#449 /wp-admin/css/colors/ectoplasm/about.php3,474
#450 /v.php3,472
#451 /file7.php3,467
#452 /wp-json/oembed3,427
#453 /wp-admin/js/wp-conflg.php3,422
#454 /c/linha-glass/robo-aspirador3,421
#455 /wp-content/plugins/about.php3,421
#456 /wp-json/wp3,420
#457 /wp-admin/css/colors/blue/about.php3,419
#458 /alfanew.php3,416
#459 /wp-admin/css/qPyYcxpHKCu.php3,410
#460 /cabelo/marcas-de-salao/wella-professionals/wella-professionals-invigo-color-brilliance-2-produtos3,408
#461 /local/.env3,402
#462 /api/v2/batch/11103,402
#463 /wp-json/sfwd-lessons3,394
#464 /.vscode/.env3,391
#465 /inc.php3,389
#466 /api/v2/products/16593698633,384
#467 /b.php3,382
#468 /a2.php3,380
#469 /wp-aa.php3,375
#470 /.aws/config3,375
#471 /y.php3,370
#472 /wp-json/sfwd-courses/13,363
#473 /.well-known/classwithtostring.php3,362
#474 /not_found3,360
#475 /wp-admin/autoload_classmap.php3,351
#476 /wp-admin/mah.php3,348
#477 /mini3,333
#478 /rest/V1/orders3,314
#479 /mail.php3,307
#480 /site/.env3,300
#481 /settings.py3,300
#482 /api/config/config.yml3,295
#483 /test/wp-includes/wlwmanifest.xml3,290
#484 /wp-admin/chosen.php3,255
#485 /prod/.env3,255
#486 /.env.old3,255
#487 /wp-json/sfwd-topic3,254
#488 /wp-admin/includes3,254
#489 /log.php3,253
#490 /api/v2/batch/11113,251
#491 /customer/account/create3,236
#492 /.AWS_/credentials3,235
#493 /wp-includes/about.php3,234
#494 /pages.php3,218
#495 /jp.php3,217
#496 /post.php3,192
#497 /tool/view/phpinfo.view.php3,189
#498 /build.php3,180
#499 /api/v2/marketplace/sellers/376/products/batch3,175
#500 /.env.production.local3,175


Data was last updated on: Jan 12, 2026



Logging Research

We love logs. In this section we will share some of the data we are parsing from our logs and honeypots we have live.

Trunc Logging

Logging for fun and a good night of sleep.

  • Real time search
  • Google simple
  • Cheap
  • Just works
  • PCI compliance
Trunc Research

Latest log-based threat analysis added.

Contact us!

Do you have an idea for a research that is not here? See something wrong? Contact us at support@noc.org

Tired of price gouging
  • Clear pricing
  • No need to guess
  • Real people
  • Real logging

Simple, Affordable, Log Management and Analysis.

14 days free trial. No credit card required.