Web logs 404 analysis - past 72 hours
Jan 31, 2026
Automatically updated daily

Checking for 404 errors in your logs can reveal more than just broken links, it can also expose files and URLs that attackers are actively scanning for. To track this behavior, we set up hundreds of honeypots and analyzed live web traffic data, giving us insight into which files and URLs are being targeted across the internet.


This table bellow list the top URLs being scanned in the past 72 hours. Some of them may show what attacker are actively looking for and new vulnerabilities in the wild.


Rank Scanned URL Counter
#1 /wp-login.php21,915
#2 /api/v2/auth20,952
#3 /index.php8,650
#4 /autodiscover/autodiscover.xml8,223
#5 /[object%20Object]4,552
#6 /.well-known/traffic-advice3,949
#7 /api/v2/products/stock-batch3,748
#8 /.well-known/passkey-endpoints3,040
#9 /4042,163
#10 /.env1,900
#11 /admin.php1,802
#12 /saiga.php1,765
#13 /file.php1,741
#14 /ccstore/v1/images1,661
#15 /ioxi-o.php1,467
#16 /about.php1,430
#17 /adminfuns.php1,386
#18 /classwithtostring.php1,290
#19 /admin1,286
#20 /info.php1,273
#21 /wp-json/oembed/1.0/embed1,270
#22 /abcd.php1,187
#23 /sources.php1,174
#24 /aa.php1,121
#25 /-/-/-/-/-/-/-/-/-/-1,077
#26 /olympikus1,066
#27 /xmlrpc.php1,010
#28 /api/v2/products/1659369592983
#29 /api/v2/products/1659370143981
#30 /api/v2/products/1659369038976
#31 /goods.php975
#32 /api/v2/products/1659369318975
#33 /.git/config975
#34 /api/v2/products/1659370315972
#35 /api/v2/products/1659372022971
#36 /api/v2/products/1659371730967
#37 /api/v2/products/1659371194966
#38 /api/v2/products/1659370539966
#39 /api/v2/products/1659369485966
#40 /api/v2/products/1659370649965
#41 /api/v2/products/1659371462965
#42 /api/v2/products/1659369765960
#43 /api/v2/products/1659369941960
#44 /api/v2/products/1659371884958
#45 /api/v2/products/1659371217954
#46 /api/v2/products/1659371029954
#47 /api/v2/products/1659370690954
#48 /api/v2/products/1659371489953
#49 /api/v2/products/1659369366951
#50 /api/v2/products/1659371220947
#51 /api/v2/products/1659370540946
#52 /api/v2/products/1659368975943
#53 /autoload_classmap.php941
#54 /api/v2/products/1659371950939
#55 /edit.php928
#56 /buy.php891
#57 /sitemap.xml844
#58 /backup831
#59 /chosen.php828
#60 /wp-admin800
#61 /wp-good.php793
#62 /shop776
#63 /checkout/cart/add763
#64 /rest/V1/salesRules746
#65 /wp-cron.php726
#66 /api/.env725
#67 /wp-json/mod/v1/clients/plugins/jcdaFPpvQo28KCS7T9Aa6BKXzTwHupSJ722
#68 /backend/.env699
#69 /wp-json/mod/v1/clients/themes/jcdaFPpvQo28KCS7T9Aa6BKXzTwHupSJ698
#70 /images/images/cache.php689
#71 /1.php687
#72 /flower.php687
#73 /cgi-bin686
#74 /admin/.env677
#75 /cong.php663
#76 /pb659
#77 /wp-json/mod/v1/clients/plugins/j6FbdsfF230jtfGKl2WXTwui8jVLt3uR650
#78 /wp-json/mod/v1/clients/themes/j6FbdsfF230jtfGKl2WXTwui8jVLt3uR647
#79 /module/ngmercadolivre/notificacao641
#80 /wp-content/themes/admin.php639
#81 /en/AutoDiscover/autodiscover.xml616
#82 /inputs.php614
#83 /file2.php610
#84 /222.php591
#85 /ccstore/v1/registry589
#86 /elp.php584
#87 /wp-trackback.php579
#88 /alfa.php568
#89 /xmrlpc.php558
#90 /api/v1/5331de46da1425c8b5f036d69da64571/json/desconto-url/dados-xml548
#91 /akcc.php545
#92 /moon.php544
#93 /wp-json/mod/v1/clients/themes/iHNBUuF2wAFhhJ1LTSZnjkZre9wu6lm8542
#94 /wp-json/mod/v1/clients/plugins/iHNBUuF2wAFhhJ1LTSZnjkZre9wu6lm8538
#95 /.well-known/apple-app-site-association536
#96 /k.php531
#97 /asasx.php522
#98 /uploads510
#99 /new.php508
#100 /.env.example500
#101 /not_found497
#102 /rip.php497
#103 /bolt.php494
#104 /administrator493
#105 /login489
#106 /admin/config.php486
#107 /bless.php481
#108 /wp-content/plugins/hellopress/wp_filemanager.php470
#109 /app_dev.php/_profiler/phpinfo470
#110 /wp.php465
#111 /contrato/wap/crons/enviar-email.php462
#112 /dropdown.php453
#113 /upload/banner450
#114 /themes.php442
#115 /wp-content/plugins/fix/up.php440
#116 /index/function.php439
#117 /atomlib.php439
#118 /makeasmtp.php429
#119 /wp-content/admin.php427
#120 /wp-json/mod/v1/clients/themes/dfH6fTJpNKPXFmf72OBbcx9a6kb73dAu422
#121 /en/autodiscover/autodiscover.xml419
#122 /wp-content/plugins/admin.php416
#123 /nc4.php409
#124 /doc.php407
#125 /image.php401
#126 /akc.php394
#127 /radio.php392
#128 /wp-content/wp-conflg.php385
#129 /wp-json/mod/v1/clients/plugins/dfH6fTJpNKPXFmf72OBbcx9a6kb73dAu383
#130 /admin/controller/extension/extension382
#131 /cdn-cgi/rum379
#132 /.git/index377
#133 /+CSCOL+/a1.jar370
#134 /+CSCOL+/Java.jar370
#135 /modules360
#136 /wp-json/mod/v1/clients/themes/N6FafVRrjaWL2s4wJW4e71UxELvdDOT5357
#137 /shell.php356
#138 /wordpress352
#139 /ss.php349
#140 /wp-json/mod/v1/clients/plugins/N6FafVRrjaWL2s4wJW4e71UxELvdDOT5340
#141 /wp-admin/images337
#142 /profile.php335
#143 /wp-json/mod/v1/clients/themes/5HEdh3eDqs6NhxAvfBJ5bWLGdvzCD248334
#144 /api/sessions333
#145 /wp-content/uploads332
#146 /wp-json/mod/v1/clients/plugins/5HEdh3eDqs6NhxAvfBJ5bWLGdvzCD248331
#147 /wp-admin/images/admin.php331
#148 /api/v2/brands/4718328
#149 /old326
#150 /wp-json/mod/v1/clients/plugins/AF6QHtkifS7afe9hYdSVzYwNUya7Deki325
#151 /wp-json/mod/v1/clients/themes/AF6QHtkifS7afe9hYdSVzYwNUya7Deki325
#152 /storage/2018/09/Educac322
#153 /user-login322
#154 /wp317
#155 /server.php316
#156 /submissions315
#157 /man.php313
#158 /register313
#159 /webapp/wcs/stores/servlet/Search311
#160 /lock360.php310
#161 /test.php309
#162 /awstats/.env309
#163 /as.php307
#164 /api/upload307
#165 /files.php306
#166 /class-t.api.php304
#167 /wp-admin/css304
#168 /app/.env302
#169 /test1.php302
#170 /wp-content/plugins/wp-diambar/includes/loadme.php298
#171 /portal/.env298
#172 /api/v2/marketplace/sellers/queue296
#173 /worksec.php294
#174 /user/login294
#175 /back/.env294
#176 /api293
#177 /wp-includes/wlwmanifest.xml293
#178 /content.php293
#179 /propolis-verde.html293
#180 /new292
#181 /w.php289
#182 /wp-includes/style-engine288
#183 /security/.env285
#184 /dev/.env283
#185 /2.php283
#186 /wp/wp-includes/wlwmanifest.xml282
#187 /web/wp-includes/wlwmanifest.xml282
#188 /admins/.env282
#189 /.well-known281
#190 /wordpress/wp-includes/wlwmanifest.xml281
#191 /lib/.env280
#192 /api/v2/marketplace/rebates/queue278
#193 /private277
#194 /ws.php277
#195 /wp-content/index.php276
#196 /blog/wp-includes/wlwmanifest.xml274
#197 /shared/.env274
#198 /wp-json/mod/v1/clients/themes/DtvNHI7xP8EXF2FuIDUJit4NDHASlM1n272
#199 /feed271
#200 /2019/wp-includes/wlwmanifest.xml271
#201 /wp-includes/Text/Diff/Renderer270
#202 /shop/wp-includes/wlwmanifest.xml270
#203 /beta/.env270
#204 /production/.env270
#205 /deepseek_d.php268
#206 /wp-content/themes/about.php267
#207 /default.php267
#208 /wp-content/plugins/WordPressCore266
#209 /t.php266
#210 /infraalert/connections.php265
#211 /alpha/.env265
#212 /cms/.env.prod264
#213 /wp-admin/css/colors/blue/index.php263
#214 /credentials262
#215 /wp-includes/rest-api261
#216 /sitemap_index.xml261
#217 /sample.env261
#218 /wp-json/mod/v1/clients/plugins/DtvNHI7xP8EXF2FuIDUJit4NDHASlM1n260
#219 /wp-admin/includes259
#220 /wp-json/mod/v1/clients/themes/3Y0UftK4ZgkOOyNentdzLR3O1XCgseZb259
#221 /community/.env259
#222 /app/config/.env258
#223 /xleet.php257
#224 /api/v2/products/531255
#225 /~admin/.env255
#226 /pos/.env252
#227 /Core/.env252
#228 /wp-admin.php251
#229 /web_api/auth250
#230 /robots/.env250
#231 /wp-includes/Requests/Exception248
#232 /wp-json/mod/v1/clients/plugins/3Y0UftK4ZgkOOyNentdzLR3O1XCgseZb248
#233 /search247
#234 /base/.env247
#235 /num.php245
#236 /django/.env245
#237 /wp-includes/ID3244
#238 /profile/.env244
#239 /travis/.env243
#240 /cc.php242
#241 /news/wp-includes/wlwmanifest.xml241
#242 /website/wp-includes/wlwmanifest.xml241
#243 /novnc/.env241
#244 /css.php240
#245 /App/__healthcheck240
#246 /gecko.php239
#247 /mail/.env239
#248 /api/v2/batch/1219238
#249 /api/v2/batch/1198238
#250 /api/v2/batch/1193238
#251 /api/v2/batch/1192238
#252 /api/v2/batch/1187238
#253 /api/v2/batch/1184238
#254 /api/v2/batch/1183238
#255 /api/v2/marketplace/sellers/364/products/queue237
#256 /api/v2/batch/1218237
#257 /api/v2/batch/1214237
#258 /api/v2/batch/1189237
#259 /api/v2/batch/1188237
#260 /api/v2/batch/1173237
#261 /api/v2/batch/1171237
#262 /api/v2/batch/1146237
#263 /api/v2/batch/1182237
#264 /api/v2/batch/1181237
#265 /api/v2/batch/1179237
#266 /api/v2/batch/1175237
#267 /api/v2/batch/1172237
#268 /api/v2/batch/1191237
#269 /api/v2/batch/1178237
#270 /bak.php236
#271 /api/v2/marketplace/sellers/351/products/queue236
#272 /4ec82611236
#273 /api/v2/marketplace/sellers/423/products/queue236
#274 /api/v2/marketplace/sellers/534/products/queue236
#275 /api/v2/batch/1194236
#276 /api/v2/batch/1190236
#277 /api/v2/batch/1177236
#278 /api/v2/batch/1174236
#279 /api/v2/marketplace/sellers/388/products/queue236
#280 /api/v2/batch/1176236
#281 /api/v2/batch/1170236
#282 /cdn-cgi/trace236
#283 /api/v2/marketplace/sellers/31/products/queue235
#284 /api/v2/marketplace/sellers/354/products/queue235
#285 /api/v2/marketplace/sellers/473/products/queue235
#286 /api/v2/marketplace/sellers/841/products/queue235
#287 /api/v2/marketplace/sellers/476/products/queue235
#288 /api/v2/marketplace/sellers/363/products/queue235
#289 /api/v2/marketplace/sellers/360/products/queue235
#290 /api/v2/marketplace/sellers/425/products/queue235
#291 /api/v2/marketplace/sellers/457/products/queue235
#292 /api/v2/marketplace/sellers/537/products/queue235
#293 /api/v2/marketplace/sellers/536/products/queue235
#294 /api/v2/marketplace/sellers/533/products/queue235
#295 /api/v2/batch/1186235
#296 /api/v2/batch/1185235
#297 /api/v2/batch/1169235
#298 /api/v2/marketplace/sellers/391/products/queue235
#299 /api/v2/marketplace/sellers/455/products/queue235
#300 /api/v2/marketplace/sellers/430/products/queue235
#301 /api/v2/marketplace/sellers/463/products/queue235
#302 /api/v2/marketplace/sellers/487/products/queue235
#303 /api/v2/marketplace/sellers/471/products/queue235
#304 /api/v2/batch/1168235
#305 /api/v2/batch/1142235
#306 /api/v2/marketplace/sellers/390/products/queue234
#307 /wp-content/plugins/yanierin/akcc.php233
#308 /ae.php233
#309 /api/v2/batch/1166233
#310 /api/v2/batch/1145233
#311 /api/v2/batch/1165232
#312 /api/v2/marketplace/sellers/655/products/queue231
#313 /wp-admin/class-db.php230
#314 /wp-includes228
#315 /13.php228
#316 /wp-content/upgrade227
#317 /adminfuns.php/.well-known/acme-challenge/file.php227
#318 /wp-json/mod/v1/clients/themes/yQYJEiML0EAKHJ1ba5G863ebauTGL4v6227
#319 /wp-includes/Text226
#320 /bin226
#321 /404.php225
#322 /wp-json/mod/v1/clients/plugins/dQbiHaYYDAThrFKTMcDQ8bWWiNvx28Yd224
#323 /wp-includes/IXR223
#324 /css/admin.php222
#325 /wp-content/about.php222
#326 /wp-admin/images/file.php220
#327 /staging/.env220
#328 /log.php219
#329 /minha-conta/pedido/2168498/detalheapi/v2/front/checkout/cart218
#330 /wp-admin/product.php217
#331 /wp-json/mod/v1/clients/themes/dQbiHaYYDAThrFKTMcDQ8bWWiNvx28Yd217
#332 /wp-content/plugins/sid/sidwso.php216
#333 /demo/.env215
#334 /blog213
#335 /file5.php211
#336 /minha-conta/pedido/2167917/detalheapi/v2/front/checkout/cart211
#337 /wp-json/mod/v1/clients/plugins/yQYJEiML0EAKHJ1ba5G863ebauTGL4v6211
#338 /defaults.php210
#339 /root.php210
#340 /rest/V1/orders209
#341 /wp-admin/js/index.php208
#342 /a.php207
#343 /wp-includes/fonts206
#344 /wp-admin/css/colors/coffee204
#345 /rest/V1/products204
#346 /wp-content/plugins/hello-dolly203
#347 /loja/casa.html203
#348 /wp-content/plugins/ultimate-member202
#349 /wp-admin/css/colors/sunrise202
#350 /manager.php202
#351 /wp-includes/pomo200
#352 /file4.php200
#353 /wp-admin/css/colors/midnight199
#354 /wp-content/plugins/gravityforms198
#355 /wordpress/wp-admin/maint198
#356 /simple.php198
#357 /wp-includes/html-api197
#358 /api/v1/7d7f91c7b727f4627bf81883ea25a347/json/pedido/atualizacoes196
#359 /api/v2/3f0803957c6b00580c1d83ddef8033ca/json/pedido/atualizacoes196
#360 /api/v1/ede49134002f41b1320469a869921657/json/pedido/atualizacoes195
#361 /api/v1/5331de46da1425c8b5f036d69da64571/json/pedido/atualizacoes195
#362 /wp-content/upgrade/index.php194
#363 /build.php194
#364 /wp-admin/network193
#365 /lowpr.php191
#366 /wp-includes/js/crop190
#367 /403.php190
#368 /api/catalog_system/pub/products/search189
#369 /sitemap-index.xml188
#370 /server/.env187
#371 /style.php187
#372 /pagamento/mercadopago/ipn.php186
#373 /owa/auth.owa185
#374 /wp-content/plugins/wp-file-manager184
#375 /wp-json/mod/v1/clients/themes/O8IPZVSpWRsNUvKGmp6tCOXPEc5pwzOf184
#376 /wp-includes/assets183
#377 /images182
#378 /wp-json/mod/v1/clients/plugins/O8IPZVSpWRsNUvKGmp6tCOXPEc5pwzOf181
#379 /wp-content/uploads/2022/07180
#380 /userlogin179
#381 /404testpage4525d2fdc179
#382 /novos-produtos.html179
#383 /test/.env177
#384 /api/v1/5331de46da1425c8b5f036d69da64571/json/produto/atualizacoes177
#385 /wp-json/mod/v1/clients/plugins/Jowup0YjuyoFl8756PugwrEu8CEOb7W176
#386 /shop/.env176
#387 /api/v1/ede49134002f41b1320469a869921657/json/produto/atualizacoes176
#388 /api/v1/7d7f91c7b727f4627bf81883ea25a347/json/produto/atualizacoes176
#389 /api/v2/3f0803957c6b00580c1d83ddef8033ca/json/produto/atualizacoes175
#390 /api/v2/products/21965174
#391 /wp-json/mod/v1/clients/themes/5HmAU7xN6qdUl3VpoGsirSopze0t5F2E174
#392 /files174
#393 /wp-content/themes/twentytwentythree173
#394 /wp-includes/images173
#395 /aaa.php171
#396 /0x.php171
#397 /2018/wp-includes/wlwmanifest.xml171
#398 /wp-content/plugins/akismet170
#399 /blog/.env170
#400 /f5.php170
#401 /p.php170
#402 /wp-content/themes/twentytwentyfour169
#403 /en/assets/images/logos/HTB.JPG169
#404 /wp-includes/PHPMailer169
#405 /wp-includes/block-supports169
#406 /wp-content/languages168
#407 /wp-content168
#408 /minha-conta-atk168
#409 /minha-conta/pedidoapi/v2/front/checkout/cart167
#410 /install.php167
#411 /assets167
#412 /wp-json/mod/v1/clients/themes/Jowup0YjuyoFl8756PugwrEu8CEOb7W166
#413 /cloud/.env166
#414 /app166
#415 /dashboard/.env165
#416 /wp-content/plugins/contact-form-7163
#417 /store/.env163
#418 /m/.env163
#419 /.env.local163
#420 /wp-content/uploads/2018/09/Educac162
#421 /vpn/.env162
#422 /webmail/.env162
#423 /remote/.env162
#424 /owa/auth/logon.aspx161
#425 /secure/.env161
#426 /sx.php161
#427 /wp-admin/js/widgets160
#428 /support/.env160
#429 /host/.env160
#430 /ultra.php159
#431 /ftp/.env159
#432 /smtp/.env158
#433 /cdn/.env158
#434 /pop/.env158
#435 /filemanager.php158
#436 /wp-plain.php158
#437 /sites/default/files157
#438 /wp-includes/css156
#439 /wp-json/mod/v1/clients/themes/222SatWljlPjOcZ6sbz9QrN2P7tPZ7fEhaw111156
#440 /wp-json/mod/v1/clients/plugins/222SatWljlPjOcZ6sbz9QrN2P7tPZ7fEhaw111156
#441 /autoload_classmap/function.php156
#442 /wiki/.env155
#443 /wp-includes/block-bindings154
#444 /.aws/credentials154
#445 /wp-bat.php154
#446 /pu9.php154
#447 /ds.php154
#448 /.well-known/acme-challenge/cloud.php153
#449 /god4m.php153
#450 /form.php152
#451 /loja/catalogo.php151
#452 /rest/V1/store/storeViews150
#453 /goat.php149
#454 /wp-content/plugins/litespeed-cache148
#455 /app/impulse/products148
#456 /wp-json/mod/v1/clients/plugins/Rw3ntZOSgnzAowBha1RvN3pidNBOtirn146
#457 /mari.php146
#458 /123.php144
#459 /0.php144
#460 /AutoDiscover/autodiscover.xml143
#461 /wp-json/mod/v1/clients/plugins/BwQrKZus03C3jAUdfG6roDDVrbF67FH1143
#462 /phpinfo.php143
#463 /include143
#464 /asd.php143
#465 /07.php143
#466 /wp-json/mod/v1/clients/plugins/5HmAU7xN6qdUl3VpoGsirSopze0t5F2E142
#467 /wp-json/mod/v1/clients/themes/Rw3ntZOSgnzAowBha1RvN3pidNBOtirn142
#468 /writer/sarah-freeman-woolpert142
#469 /assets/images142
#470 /berax.php142
#471 /axx.php142
#472 /Jcrop.php141
#473 /hplfuns.php141
#474 /wp1/wp-includes/wlwmanifest.xml139
#475 /wp-includes/widgets138
#476 /play/aula/conteudo/buscar/4365382137
#477 /wp-json/mod/v1/clients/themes/iuyhN4wenVAqT45GUz5UTZJS7XwKw1a8137
#478 /x.php137
#479 /cache.php137
#480 /wp-json/mod/v1/clients/plugins/iuyhN4wenVAqT45GUz5UTZJS7XwKw1a8136
#481 /phpinfo136
#482 /wp-admin/setup-config.php135
#483 /wp-json/mod/v1/clients/plugins/XbPUmQItjloTIWA6BLYFIH9kLKopOaPg134
#484 /zona-livre133
#485 /_next133
#486 /kyami.php133
#487 /wp-json/mod/v1/clients/themes/XbPUmQItjloTIWA6BLYFIH9kLKopOaPg132
#488 /wp-json/mod/v1/clients/plugins/AVrzZ53ziRyZEhVINNEiHcUOgJbgJrOP132
#489 /mm.php132
#490 /lufix.php132
#491 /new/.env132
#492 /akismet.php130
#493 /hello.php130
#494 /admin/function.php130
#495 /apps/.env130
#496 /wp-content/cache128
#497 /wp-json/mod/v1/clients/themes/AVrzZ53ziRyZEhVINNEiHcUOgJbgJrOP128
#498 /version128
#499 /al.php128
#500 /wp-content/plugins/elementor127


Data was last updated on: Jan 31, 2026



Logging Research

We love logs. In this section we will share some of the data we are parsing from our logs and honeypots we have live.

Trunc Logging

Logging for fun and a good night of sleep.

  • Real time search
  • Google simple
  • Cheap
  • Just works
  • PCI compliance
Trunc Research

Latest log-based threat analysis added.

Contact us!

Do you have an idea for a research that is not here? See something wrong? Contact us at support@noc.org

Tired of price gouging
  • Clear pricing
  • No need to guess
  • Real people
  • Real logging

Simple, Affordable, Log Management and Analysis.

14 days free trial. No credit card required.