Web logs 404 analysis - past 72 hours
Oct 7, 2025
Automatically updated daily

Checking for 404 errors in your logs can reveal more than just broken links, it can also expose files and URLs that attackers are actively scanning for. To track this behavior, we set up hundreds of honeypots and analyzed live web traffic data, giving us insight into which files and URLs are being targeted across the internet.


This table bellow list the top URLs being scanned in the past 72 hours. Some of them may show what attacker are actively looking for and new vulnerabilities in the wild.


Rank Scanned URL Counter
#1 /wp-login.php17,844
#2 /201217,699
#3 /sitemap.xml13,898
#4 /xmlrpc.php9,330
#5 /index.php7,501
#6 /module/ngmercadolivre/notificacao6,332
#7 /wp-content/plugins/fix/up.php4,531
#8 /.well-known/traffic-advice4,502
#9 /404testpage4525d2fdc4,115
#10 /.env3,959
#11 /wp-cron.php3,482
#12 /api/v2/categories/653,239
#13 /login3,027
#14 /foq.php2,714
#15 /rest/V1/store/storeViews2,532
#16 /07550e182,471
#17 /api/v2/categories/642,294
#18 /cabelos/creme-tratamento-silicon-mix2,111
#19 /boaform/admin/formLogin2,091
#20 /api/v2/marketplace/sellers/376/products/status-batch2,085
#21 /.git/config2,066
#22 /api/v2/marketplace/sellers/376/products/stock-batch2,037
#23 /api/v2/marketplace/sellers/376/products/price-batch2,026
#24 /en/AutoDiscover/autodiscover.xml1,988
#25 /user/login1,973
#26 /pagamento/mercadopago/ipn.php1,924
#27 /en/autodiscover/autodiscover.xml1,871
#28 /wp-sitemap.xml1,779
#29 /wp-admin/edit-tags.php1,772
#30 /admin.php1,765
#31 /wp-admin/post-new.php1,601
#32 /wiki1,591
#33 /about.php1,575
#34 /info.php1,484
#35 /sk_es/vozik1,419
#36 /wp-includes/wlwmanifest.xml1,398
#37 /contrato/wap/crons/enviar-email.php1,387
#38 /sitemap.php1,368
#39 /manager/html1,329
#40 /linha-bruna-tavares/tudo-sobre-o-bt-lux1,297
#41 /_profiler/phpinfo1,281
#42 /api/v2/customers/login1,257
#43 /wp-json/sfwd-assignment/11,251
#44 /faqs.php1,247
#45 /wp-json/oembed/1.0/embed1,245
#46 /wp-admin1,196
#47 /hinos-do-povo-de-deus/conteudo.php1,134
#48 /web/wp-includes/wlwmanifest.xml1,129
#49 /wordpress/wp-includes/wlwmanifest.xml1,128
#50 /.well-known/nodeinfo1,126
#51 /wp/wp-includes/wlwmanifest.xml1,106
#52 /backend1,096
#53 /4041,096
#54 /sitemap_index.xml1,096
#55 /admin1,095
#56 /api/v2/freights/3161,094
#57 /cms1,073
#58 /2019/wp-includes/wlwmanifest.xml1,065
#59 /shop/wp-includes/wlwmanifest.xml1,063
#60 /blog/wp-includes/wlwmanifest.xml1,059
#61 /website/wp-includes/wlwmanifest.xml1,043
#62 /news/wp-includes/wlwmanifest.xml1,035
#63 /backup1,003
#64 /cursogratuito/ola-mundo964
#65 /feed/mnpodcast961
#66 /panel953
#67 /admin/config.php938
#68 /cigarettesoo.php918
#69 /pb918
#70 /sitemap_index_16.xml899
#71 /tag/paolla-oliveira/page/3867
#72 /maquiagem/heavy-metal-loose-glitter-loaded-da-urban-decay852
#73 /api/v2/marketplace/sellers/615/products/queue841
#74 /sitemap-index.xml841
#75 /assistente-virtual-tfg819
#76 /phpinfo815
#77 /wp-json/wp-mail-smtp814
#78 /wp-json/publishpress-authors810
#79 /snc-tfg809
#80 /test.php804
#81 /api/v2/marketplace/sellers/655/products/queue802
#82 /login-2801
#83 /sitemap_index_31.xml800
#84 /wp-json/wp799
#85 /file.php792
#86 /wp-json/penci788
#87 /dd.php785
#88 /api/v2/marketplace/sellers/376/products/queue783
#89 /wp-json/oembed782
#90 /sitemap_index_0.xml778
#91 /cigarettesdd.php772
#92 /sitemap_index_9.xml764
#93 /sitemap_index_1.xml762
#94 /sitemap_index_27.xml758
#95 /loja/catalogo.php753
#96 /sitemap_index_15.xml751
#97 /sitemap_index_5.xml743
#98 /wp-admin/images736
#99 /sitemap_index_17.xml735
#100 /autodiscover/autodiscover.xml734
#101 /dashboard730
#102 /wp-json/sfwd-lessons/1726
#103 /sitemap_index_11.xml725
#104 /wp-admin/css723
#105 /sitemap_index_19.xml716
#106 /wp-json/wp-block-editor712
#107 /wp-json/gravity-pdf704
#108 /sitemap_index_8.xml703
#109 /wp-json/gwiz702
#110 /sitemap_index_14.xml695
#111 /wp-json/elementor-pro694
#112 /wp-json/sfwd-courses/17/prerequisites693
#113 /sitemap_index_30.xml692
#114 /wp-json/aioseo692
#115 /wp-json/webp-converter690
#116 /wordpress688
#117 /wp-json/akismet682
#118 /wp-json/elementor-ai682
#119 /sitemap_index_18.xml677
#120 /wp-json/wccom-site674
#121 /wp-json/google-site-kit670
#122 /index.html664
#123 /wp-json/sfwd-courses/17/groups661
#124 /sitemap_index_33.xml660
#125 /sitemap_index_4.xml658
#126 /sitemap_index_32.xml658
#127 /myk.php656
#128 /wp-json/sfwd-topic/1648
#129 /server-status647
#130 /sitemap_index_23.xml646
#131 /sitemap_index_24.xml645
#132 /sitemap_index_20.xml644
#133 /chosen.php641
#134 /sitemap_index_12.xml639
#135 /wp.php636
#136 /2018/wp-includes/wlwmanifest.xml630
#137 /api/v2/products/5000013907629
#138 /sitemap_index_10.xml623
#139 /sitemap_index_29.xml621
#140 /sitemap_index_21.xml620
#141 /wp618
#142 /sitemap_index_28.xml617
#143 /sitemap_index_3.xml608
#144 /sitemap_index_25.xml607
#145 /.well-known/passkey-endpoints603
#146 /old587
#147 /1.php586
#148 /sitemap_index_26.xml585
#149 /bc582
#150 /sitemap_index_7.xml581
#151 /2008/10/ossec-presentation-at-ottsec581
#152 /home581
#153 /telescope/requests576
#154 /assets/images/accesson.php575
#155 /cigarettesww.php574
#156 /SistemaEAD_CPREM/login/index.php574
#157 /2007/06/ossec-presentations-at-auscertconfidence572
#158 /sitemap_index_22.xml568
#159 /sitemap_index_13.xml563
#160 /sitemap_index_2.xml560
#161 /tag/sabonete/page/3559
#162 /api547
#163 /shopdetail/sitemap-hot-1983615.xml545
#164 /xml/images.xml545
#165 /sitemap_index_6.xml542
#166 /bk538
#167 /tool/view/phpinfo.view.php537
#168 /wp-json/sfwd-assignment/0532
#169 /shopdetail/sitemap-hot-1973615.xml530
#170 /pesca/login/index.php527
#171 /main526
#172 /loja/login_layout.php523
#173 /bins521
#174 /shopdetail/sitemap-hot-1985615.xml519
#175 /v2/_catalog506
#176 /@vite/env503
#177 /maquiagem/tutorial-com-sombra-chumbo-e-azul497
#178 /login.action494
#179 /about493
#180 /shopdetail/sitemap-hot-1987615.xml485
#181 /loja/arquivos/1049375/sitemaps/sitemap_1.xml484
#182 /akcc.php479
#183 /2020/wp-includes/wlwmanifest.xml477
#184 /images/images/cache.php474
#185 /api/v2/batch/1110469
#186 /new469
#187 /rest/V1/orders465
#188 /api/v2/marketplace/sellers/655/orders/queue464
#189 /index.php/api/soap463
#190 /api/v2/batch/1371462
#191 /version462
#192 /bin462
#193 /api/v2/batch/1392460
#194 /api/v2/batch/1394455
#195 /shopdetail/sitemap-hot-1991615.xml454
#196 /api/v2/batch/1148450
#197 /api/v2/batch/1100442
#198 /api/v2/batch/1102441
#199 /akc.php441
#200 /api/v2/batch/1396438
#201 /api/v2/batch/1129437
#202 /api/v2/batch/1390435
#203 /wp-content/plugins/hellopress/wp_filemanager.php434
#204 /api/v2/batch/1386432
#205 /api/v2/batch/1099432
#206 /api/v2/batch/1103431
#207 /.well-known/sg-hosted-ping430
#208 /api/v2/batch/1387430
#209 /api/v2/batch/1388429
#210 /api/v2/batch/1145429
#211 /api/v2/batch/1373429
#212 /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php427
#213 /vocabulario/aprendizagem427
#214 /sites/all/libraries/plupload/examples/upload.php427
#215 /api/v2/batch/1121425
#216 /vocabulario/taxonomia__trashed424
#217 /api/v2/batch/1397421
#218 /api/v2/batch/1125421
#219 /abcd.php421
#220 /api/v2/batch/1118420
#221 /api/v2/batch/1372420
#222 /api/v2/batch/1146420
#223 /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application420
#224 /api/v2/batch/1391419
#225 /api/v2/batch/1395419
#226 /api/v2/batch/1128418
#227 /api/v2/marketplace/sellers/615/orders/queue417
#228 /api/v2/batch/1399416
#229 /api/v2/batch/1123416
#230 /css.php414
#231 /api/v2/marketplace/sellers/376/products/batch413
#232 /api/v2/batch/1400413
#233 /HNAP1412
#234 /api/v2/batch/1393411
#235 /api/v2/batch/1401410
#236 /api/v2/batch/1398410
#237 /api/v2/batch/1113409
#238 /api/v2/batch/1124406
#239 /api/v2/batch/1126405
#240 /api/v2/batch/1116405
#241 /api/v2/batch/1115405
#242 /api/v2/batch/1127405
#243 /api/v2/batch/1119404
#244 /api/v2/batch/1149403
#245 /doc.php403
#246 /www.medsam.com.br/neurodyn-II-tens-fes-russa-ibramed401
#247 /debug/default/view398
#248 /wp-json/sfwd-lessons397
#249 /api/v2/batch/1114396
#250 /api/v2/batch/1112395
#251 /.git/index394
#252 /wp-json/wc/v2/products391
#253 /api/v2/batch/1098391
#254 /api/v2/batch/1101391
#255 /wp-plain.php391
#256 /simple.php390
#257 /atomlib.php388
#258 /wp-json/sfwd-courses388
#259 /api/v2/batch/1120385
#260 /shopdetail/sitemap.xml384
#261 /api/v2/batch/1117383
#262 /api/v2/batch/1122382
#263 /item/Caique-Brudden-Explorer-Fishing-Up-.html382
#264 /autoload_classmap.php382
#265 /test381
#266 /blogcid10379
#267 /wp1/wp-includes/wlwmanifest.xml379
#268 /api/v2/batch/1109378
#269 /shopdetail/sitemap-hot-1993615.xml376
#270 /blogbulario376
#271 /lock360.php373
#272 /test1.html371
#273 /web371
#274 /wp-editor.php364
#275 /.well-known/acme-challenge/about.php360
#276 /bless.php360
#277 /%22https:/pagead2.googlesyndication.com/pagead/gen_204359
#278 /wp-json/sfwd-topic359
#279 /wp-json/sfwd-courses/[]/users359
#280 /api/v2/batch/1111355
#281 /checkout/cart/add355
#282 /server355
#283 /shopdetail/sitemap-hot-1971615.xml353
#284 /loja/cartService.php353
#285 /2009/01/ossec-book-as-best-book-bejtlich-read-in-2008348
#286 /sitemap_index_35.xml347
#287 /manager.php347
#288 /_all_dbs345
#289 /www.medsam.com.br/beauty-face-alta-frequencia-portatil-HTM343
#290 /as.php343
#291 /xml/xml.php342
#292 /api/v2/marketplace/sellers/376/orders/queue335
#293 /shopdetail/sitemap-hot-1967615.xml334
#294 /blognoticias333
#295 /feed333
#296 /www.medsam.com.br/plasmax-aparelho-de-jato-de-plasma-portatil-kld333
#297 /contato332
#298 /phpinfo.php332
#299 /wp-content/themes/twentytwentythree/styles/about.php332
#300 /radio.php329
#301 /gifclass.php328
#302 /actuator/env328
#303 /administrator327
#304 /makeasmtp.php326
#305 /shopdetail/sitemap-hot-1989615.xml325
#306 /evox/about325
#307 /shopdetail/sitemap-hot-1963615.xml323
#308 /sdk322
#309 /RDWeb/Pages321
#310 /2010/10/ossec-award-daemon/"320
#311 /wp-content/themes/seotheme/db.php319
#312 /shopdetail/sitemapmobileindex.xml318
#313 /marcas/keune318
#314 /zwso.php318
#315 /style.php318
#316 /class-t.api.php317
#317 /v1313
#318 /shopdetail/sitemap-hot-1981615.xml312
#319 /AutoDiscover/autodiscover.xml312
#320 /inputs.php310
#321 /api/graphql308
#322 /shopdetail/sitemap-hot-1969615.xml307
#323 /lv.php307
#324 /shopdetail/sitemap-hot-1965615.xml306
#325 /www.medsam.com.br/Beauty-Steam-Maxx-Vapor-de-Ozonio-HTM304
#326 /api/v2/freights/340304
#327 /sitemap_index_36.xml302
#328 /shopdetail/sitemapindex.xml302
#329 /sitemap_index_34.xml302
#330 /www.medsam.com.br/novo-dermosteam-led-e-vapor-de-ozonio-ibramed302
#331 /bolt.php300
#332 /alfa.php299
#333 /php_info.php299
#334 /customer/account/create298
#335 /flower.php298
#336 /cong.php297
#337 /shopdetail/sitemap-hot-1977615.xml294
#338 /melhores-ofertas/escolha-seu-cadiveu294
#339 /shopdetail/sitemap-hot-1975615.xml290
#340 /api/v2/batch/1369290
#341 /wp-json/sfwd-assignment290
#342 /CDGServer3/SystemConfig288
#343 /shopdetail/sitemap-hot-1979615.xml287
#344 /www.medsam.com.br/novo-beauty-dermo-aparelho-de-vacuoterapia-e-ventosaterapia-htm286
#345 /classwithtostring.php286
#346 /files285
#347 /api/.env285
#348 /mah.php284
#349 /popup/checkout283
#350 /loja/carrinho.php282
#351 /goods.php276
#352 /play/11051837274
#353 /wp-admin/wp-login.php273
#354 /s/1313e2236313e20373e2538313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties272
#355 /login.html271
#356 /wp-content/plugins/about.php270
#357 /www.medsam.com.br/sonopulse-iii-ultrassom-1-3mhz-ibramed269
#358 /dana-na/auth/url_default/welcome.cgi265
#359 /-/-/-/-/-/-/-/-/-/-265
#360 /cool.php265
#361 /jmx-console261
#362 /appWP/lab/wp-admin/css/colors/blue/blue.php261
#363 /images260
#364 /wp-content/themes/modular/lib/scripts/timthumb/thumb.php259
#365 /buy.php258
#366 /event/ceo-2ic-peer-2-peer-retreat252
#367 /test/wp-includes/wlwmanifest.xml251
#368 /api/v2/marketplace/sellers/631/products/queue251
#369 /2010/10/ossec-award-daemon/%22250
#370 /go.php250
#371 /v2.php250
#372 /daniela-imai-lima/guia-de-compras-por-uma-farmacia-japonesa249
#373 /api/v2/batch/1363249
#374 /wp-admin/setup-config.php249
#375 /NewFile.php247
#376 /files.php246
#377 /busca244
#378 /we.php244
#379 /event/high-functioning-mission-teams-p2p239
#380 /wp-content239
#381 /cuidados-com-os-cabelos/marcas238
#382 /moon.php238
#383 /form.html237
#384 /wp-content/themes/style.php237
#385 /site/wp-includes/wlwmanifest.xml236
#386 /uploads236
#387 /noc-cdn/index.php236
#388 /cms/wp-includes/wlwmanifest.xml235
#389 /login.php235
#390 /api/v2/batch/1365235
#391 /sitemaps.xml235
#392 /ioxi-o.php234
#393 /cgi-bin/luci/;stok=/locale233
#394 /11.php233
#395 /integracoes/api/v2/auth232
#396 /wp-content/style.php232
#397 /wp-json/commerce/paypal/payments/order231
#398 /c.php230
#399 /api/v2/marketplace/sellers/631/products/batch228
#400 /api/v2/batch/1364227
#401 /event/chairside-3d-printing-digital-smile-design226
#402 /geju.php226
#403 /card.php226
#404 /api/v2/batch/1360225
#405 /systembc/password.php225
#406 /karak.php225
#407 /shell.php224
#408 /admin/index.php224
#409 /agua-inglesa-e-capaz-de-ajudar-a-engravidar-saiba-mais222
#410 /blog221
#411 /undefined221
#412 /themes.php221
#413 /wp-admin/style.php220
#414 /Form219
#415 /sitemap.xml.gz217
#416 /fm.php217
#417 /a.php217
#418 /en/assets/images/logos/HTB.JPG215
#419 /esportes/tenis-para-corrida/on-running215
#420 /member-signup214
#421 /config.php214
#422 /api/v2/batch/1362213
#423 /0.php212
#424 /owa/auth.owa212
#425 /api/v2/batch/1358211
#426 /wp-22.php211
#427 /api/v2/batch/1366210
#428 /xx.php210
#429 /wpcx.php209
#430 /modules.php208
#431 /solr/admin/collections208
#432 /en_gb/login-3208
#433 /noticia.php207
#434 /zoo.php207
#435 /geoip207
#436 /wp-json/commerce/paypal/payments/start-trial207
#437 /upl.php206
#438 /t4205
#439 /default.php204
#440 /rss.php204
#441 /password.php204
#442 /user-login203
#443 /install.php203
#444 /api/v2/customers/null203
#445 /dropdown.php202
#446 /groups%22%22202
#447 /expansao-franquia200
#448 /wpc.php200
#449 /222.php200
#450 /ar.php200
#451 /gmo.php199
#452 /file1.php199
#453 /web_api/auth198
#454 /api/v2/batch/1359198
#455 /api/sessions196
#456 /byp.php196
#457 /1-8195
#458 /admin/controller/extension/extension195
#459 /backup.php195
#460 /wso.php194
#461 /api/v2/products/5000013928193
#462 /blurbs.php192
#463 /backup2.php192
#464 /wp-content/uploads/oxygen/css/none191
#465 /wp-json/wc/v2/orders191
#466 /wp-json/wc/v2/settings/wc_admin/woocommerce_excluded_report_order_statuses191
#467 /wp-json/wc/v2/payment_gateways191
#468 /elp.php191
#469 /wp-content/plugins/hellopress/wp_mna.php190
#470 /wp-json/wc/v2/taxes188
#471 /sites/default/files188
#472 /loja/busca.php188
#473 /administrator/index.php187
#474 /class.php187
#475 /comment-page-1186
#476 /mini.php186
#477 /num.php186
#478 /rest/applinks/1.0/manifest186
#479 /wp-login185
#480 /asdf.php185
#481 /123.php185
#482 /xmrlpc.php184
#483 /alfanew.php183
#484 /wp-includes/css182
#485 /about/function.php182
#486 /nc4.php182
#487 /index/function.php181
#488 /cache.php181
#489 /api/v2/freights/344180
#490 /laravel/.env177
#491 /wp2/wp-includes/wlwmanifest.xml176
#492 /actutor/env175
#493 /app174
#494 /solr/admin/cores173
#495 /shlo.php173
#496 /contact172
#497 /.aws/credentials172
#498 /app/.env172
#499 /owa171
#500 /flex.php171


Data was last updated on: Oct 7, 2025



Logging Research

We love logs. In this section we will share some of the data we are parsing from our logs and honeypots we have live.

Trunc Logging

Logging for fun and a good night of sleep.

  • Real time search
  • Google simple
  • Cheap
  • Just works
  • PCI compliance
Trunc Research

Latest log-based threat analysis added.

Contact us!

Do you have an idea for a research that is not here? See something wrong? Contact us at support@noc.org

Tired of price gouging
  • Clear pricing
  • No need to guess
  • Real people
  • Real logging

Simple, Affordable, Log Management and Analysis.

14 days free trial. No credit card required.