Web logs 404 analysis - past 72 hours
Sep 17, 2025
Automatically updated daily

Checking for 404 errors in your logs can reveal more than just broken links, it can also expose files and URLs that attackers are actively scanning for. To track this behavior, we set up hundreds of honeypots and analyzed live web traffic data, giving us insight into which files and URLs are being targeted across the internet.


This table bellow list the top URLs being scanned in the past 72 hours. Some of them may show what attacker are actively looking for and new vulnerabilities in the wild.


Rank Scanned URL Counter
#1 /wp-login.php30,016
#2 /xmlrpc.php7,678
#3 /wp-json/oembed/1.0/embed7,504
#4 /sitemap.xml6,133
#5 /.env5,355
#6 /module/ngmercadolivre/notificacao4,552
#7 /wp-cron.php3,064
#8 /api/v2/categories/643,041
#9 /.git/config3,011
#10 /.well-known/traffic-advice2,834
#11 /file.php2,635
#12 /api/v2/categories/652,549
#13 /index.php2,356
#14 /rest/V1/store/storeViews2,268
#15 /4042,226
#16 /search2,010
#17 /info.php1,992
#18 /chosen.php1,944
#19 /en/AutoDiscover/autodiscover.xml1,790
#20 /api/v3/community1,761
#21 /wordpress1,755
#22 /wp1,591
#23 /old1,585
#24 /backup1,564
#25 /main1,534
#26 /pagamento/mercadopago/ipn.php1,517
#27 /atomlib.php1,485
#28 /bk1,468
#29 /bc1,460
#30 /new1,446
#31 /admin.php1,405
#32 /wp-admin1,402
#33 /wp-content/plugins/fix/up.php1,400
#34 /style.php1,385
#35 /.well-known/nodeinfo1,334
#36 /goat.php1,331
#37 /file2.php1,327
#38 /lock360.php1,304
#39 /about.php1,303
#40 /login1,279
#41 /aa.php1,259
#42 /wp-includes/wlwmanifest.xml1,239
#43 /autoload_classmap.php1,239
#44 /en/autodiscover/autodiscover.xml1,231
#45 /akc.php1,186
#46 /contact1,161
#47 /alfa.php1,159
#48 /makeasmtp.php1,155
#49 /contact-us1,136
#50 /manager/html1,129
#51 /test1,124
#52 /contato.html1,108
#53 /ioxi-o.php1,107
#54 /HNAP11,106
#55 /wp-content/plugins/hellopress/wp_filemanager.php1,105
#56 /flower.php1,100
#57 /classwithtostring.php1,098
#58 /wp.php1,090
#59 /contatos.html1,089
#60 /faleconosco1,082
#61 /cong.php1,070
#62 /contatos1,069
#63 /server-status1,068
#64 /goods.php1,059
#65 /fale-conosco1,053
#66 /web/wp-includes/wlwmanifest.xml1,041
#67 /contate1,035
#68 /wordpress/wp-includes/wlwmanifest.xml1,032
#69 /wp-admin/images/moon.php1,030
#70 /telescope/requests1,028
#71 /contate-nos1,027
#72 /.well-known/acme-challenge/about.php1,026
#73 /wp/wp-includes/wlwmanifest.xml1,023
#74 /api/v2/categories/861,023
#75 /404testpage4525d2fdc1,012
#76 /nc4.php991
#77 /autoload_classmap/function.php991
#78 /wp-content/plugins/wpterm.php990
#79 /2019/wp-includes/wlwmanifest.xml984
#80 /wp-content/style.php981
#81 /blog/wp-includes/wlwmanifest.xml977
#82 /home974
#83 /shop/wp-includes/wlwmanifest.xml974
#84 /website/wp-includes/wlwmanifest.xml974
#85 /suporte965
#86 /news/wp-includes/wlwmanifest.xml961
#87 /v2/_catalog960
#88 /admin952
#89 /contato943
#90 /debug/default/view933
#91 /_profiler/phpinfo933
#92 /edit.php910
#93 /loja/catalogo.php907
#94 /buy.php889
#95 /wp-admin/setup-config.php881
#96 /asasx.php866
#97 /users.php865
#98 /tinyfilemanager.php859
#99 /w.php850
#100 /mm.php846
#101 /wp-admin/css815
#102 /.well-known/apple-app-site-association812
#103 /CLA.php806
#104 /wsa.php797
#105 /wp-setup.php780
#106 /wp-content/wp-conflg.php769
#107 /wp-api.php769
#108 /login.action761
#109 /images/images/cache.php756
#110 /wp-sitemap.xml756
#111 /wp-admin/style.php755
#112 /test.php750
#113 /phpinfo741
#114 /about733
#115 /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application728
#116 /.well-known/acme-challenge/muse.php725
#117 /@vite/env722
#118 /server718
#119 /_all_dbs718
#120 /wp-includes/fonts/admin.php718
#121 /wp-includes/IXR/autoload_classmap.php711
#122 /wp-plain.php701
#123 /actuator/env697
#124 /public/.env692
#125 /dynip/f282640c685
#126 /wp-content/index.php666
#127 /api/.env658
#128 /gecko.php654
#129 /core/.env653
#130 /Form644
#131 /07550e18631
#132 /wp-admin/js/index.php626
#133 /loja/login_layout.php622
#134 /cool.php621
#135 /222.php599
#136 /laravel/.env598
#137 /cgi-bin/luci/;stok=/locale587
#138 /app/.env582
#139 /wp-admin/css/colors/blue/index.php581
#140 /administrator580
#141 /2018/wp-includes/wlwmanifest.xml577
#142 /wp-content/themes/style.php563
#143 /.well-known/acme-challenge/cloud.php562
#144 /1.php557
#145 /13.php555
#146 /des.php552
#147 /sites/all/libraries/kcfinder/upload.php541
#148 /s/1313e2236313e20373e2538313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties541
#149 /.git/index535
#150 /wp-includes/fonts/index.php532
#151 /index.html527
#152 /web520
#153 /web/.env518
#154 /user/login517
#155 /.well-known/passkey-endpoints517
#156 /lv.php516
#157 /manager.php515
#158 /ava.php512
#159 /phpinfo.php508
#160 /dropdown.php507
#161 /-/-/-/-/-/-/-/-/-/-507
#162 /ffile.php505
#163 /gfile.php504
#164 /sdk495
#165 /evox/about493
#166 /inputs.php493
#167 /admin/.env491
#168 /backend/.env489
#169 /we.php476
#170 /.env.example469
#171 /axx.php469
#172 /wp-editor.php457
#173 /bolt.php451
#174 /assets/plugins/kcfinder/upload.php450
#175 /pb449
#176 /gmo.php449
#177 /as.php443
#178 /default.php434
#179 /2020/wp-includes/wlwmanifest.xml433
#180 /site/.env430
#181 /asset/kcfinder/upload.php429
#182 /prod/.env428
#183 /files427
#184 /.env.bak422
#185 /file5.php421
#186 /error.php415
#187 /rsnu.php415
#188 /rest/V1/orders413
#189 /3.php413
#190 /uploads412
#191 /index.php/api/soap412
#192 /assets/kcfinder/upload.php412
#193 /pp.php410
#194 /api409
#195 /kcfinder/upload.php409
#196 /js/kcfinder/upload.php409
#197 /images408
#198 /admin/controller/extension/extension406
#199 /cfile.php405
#200 /dev/.env404
#201 /simple.php404
#202 /file1.php401
#203 /assets/js/kcfinder/upload.php401
#204 /sites/default/files400
#205 /local/.env399
#206 /api/v2/customers/login399
#207 /abcd.php397
#208 /file17.php397
#209 /.well-known/web-identity397
#210 /f35.php393
#211 /.well-known/webauthn393
#212 /.well-known/change-password393
#213 /wp-content/themes/seotheme/db.php392
#214 /contrato/wap/crons/enviar-email.php392
#215 /plugins/kcfinder/upload.php391
#216 /.well-known/resource-that-should-not-exist-whose-status-code-should-not-be-200391
#217 /database/.env389
#218 /feed/mnpodcast389
#219 /ckeditor/plugins/kcfinder/upload.php389
#220 /admin/index.php385
#221 /cms384
#222 /.well-known/acme-challenge/xmrlpc.php383
#223 /application/.env382
#224 /js/tinymce/kcfinder/upload.php380
#225 /php.php376
#226 /lib/kcfinder/upload.php376
#227 /api/v2/freights/316374
#228 /admin/config.php374
#229 /yasnu.php373
#230 /form.html372
#231 /ioxi2.php371
#232 /cc.php370
#233 /yanki.php370
#234 /gm.php370
#235 /fe5.php370
#236 /apiundefined370
#237 /ckeditor/kcfinder/upload.php366
#238 /wordpress/wp-admin/setup-config.php362
#239 /blog360
#240 /cron/.env359
#241 /member-signup357
#242 /upl.php356
#243 /t4356
#244 /new/.env355
#245 /password.php355
#246 /systembc/password.php355
#247 /geoip355
#248 /ola-mundo355
#249 /new4.php353
#250 /php_info.php352
#251 /wp-admin/js350
#252 /a2.php350
#253 /shell1.php350
#254 /class.1.php350
#255 /jmfi2.php350
#256 /doc.php348
#257 /gfile1.php348
#258 /cache.php347
#259 /_phpinfo.php346
#260 /www/.env343
#261 /mar.php343
#262 /js/.env342
#263 /resp.php342
#264 /apps/.env340
#265 /wp1/wp-includes/wlwmanifest.xml340
#266 /shell.php338
#267 /wiki338
#268 /file7.php338
#269 /444.php337
#270 /main/.env336
#271 /docker/.env334
#272 /env/.env334
#273 /g1.php333
#274 /awstats/.env331
#275 /crm/.env327
#276 /mail/.env326
#277 /not_found324
#278 /k.php322
#279 /file4.php320
#280 /ext.php318
#281 /development/.env317
#282 /css.php317
#283 /wp-update.php317
#284 /www.ifs.se/about-ifs/ifs-policies/ifs-cookie-policy.html317
#285 /.env.prod316
#286 /config/aws.yml312
#287 /aws.yml311
#288 /old-application-forms311
#289 /noc-cdn309
#290 /www.ifs.se/about-ifs309
#291 /checkout/cart/add308
#292 /file88.php308
#293 /Website308
#294 /www.esipps-int.org308
#295 /Math.PI*180307
#296 /ifs-grantees/the-comstech307
#297 /file9.php306
#298 /file3.php306
#299 /file6.php306
#300 /programme306
#301 /new.php305
#302 /assets/components/resources/assets/components/resources/PIE.htc305
#303 /loja/carrinho.php304
#304 /s*,s*304
#305 /www.ifs.se304
#306 /031.php303
#307 /filesss.php303
#308 /www.neotropico.net303
#309 /usep.php302
#310 /dfre.php302
#311 /ilex.php302
#312 /vast.php302
#313 /cccc.php302
#314 /eauu.php302
#315 /fs.php302
#316 /keu.php302
#317 /file13.php302
#318 /file32.php302
#319 /y.php301
#320 /hexx.php301
#321 /lala.php301
#322 /520.php301
#323 /file18.php301
#324 /efile.php301
#325 /SistemaEAD_CPREM/login/index.php300
#326 /.aws/credentials300
#327 /an.php299
#328 /autoria-e-traducao-das-letras-dos-hinos-do-hpd-1/conteudo.php298
#329 /num.php298
#330 /version295
#331 /wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot294
#332 /moon.php288
#333 /sitemap_index_16.xml287
#334 /ab2h287
#335 /ab2g287
#336 /contacts.php287
#337 /akcc.php286
#338 /teorema505286
#339 /alive.php286
#340 /status.php284
#341 /tox.php283
#342 /boaform/admin/formLogin282
#343 /remote/login279
#344 /gifclass.php278
#345 /radio.php278
#346 /files.php278
#347 /app_dev.php/_profiler/phpinfo277
#348 /.git/HEAD277
#349 /333.php274
#350 /query273
#351 /wp-control.php273
#352 /vendor/.env271
#353 /portal/.env271
#354 /aa17.php269
#355 /hk.php269
#356 /solr/admin/cores268
#357 /sitemap_index_14.xml268
#358 /sitemap_index.xml267
#359 /667.php265
#360 /conf/.env264
#361 /.well-known263
#362 /classsmtps.php263
#363 /wp-content262
#364 /ervin-cordero/track/single262
#365 /zeal.php262
#366 /sitemap_index_15.xml261
#367 /wp-admin/autoload_classmap.php261
#368 /wp-json/wp261
#369 /sitemap_index_1.xml260
#370 /new/.env.local260
#371 /ssss.php260
#372 /_profiler/phpinfo/info.php260
#373 /aws-secret.yaml260
#374 /.env.local259
#375 /sitemap_index_27.xml259
#376 /server-info259
#377 /a.php259
#378 /g.php259
#379 /storage/.env258
#380 /nope.php258
#381 /wp-json/oembed258
#382 /wp-content/themes/about.php257
#383 /sitemap_index_5.xml257
#384 /sitemap_index_19.xml257
#385 /new/.env.staging256
#386 /sendgrid.env256
#387 /_profiler/phpinfo/phpinfo.php255
#388 /lc.php255
#389 /backend254
#390 /sitemap_index_11.xml254
#391 /stalker_portal/server/tools/auth_simple.php254
#392 /en/.env252
#393 /laravel/info.php252
#394 /new/.env.production252
#395 /lara/info.php252
#396 /sitemap_index_32.xml252
#397 /elf.php252
#398 /feed251
#399 /wp-config251
#400 /panel251
#401 /xampp/phpinfo.php249
#402 /lara/phpinfo.php249
#403 /settings.py249
#404 /sitemap_index_0.xml249
#405 /sitemap_index_31.xml248
#406 /sitemap_index_17.xml248
#407 /docker/app/.env248
#408 /loja/arquivos/1049375/sitemaps/sitemap_1.xml248
#409 /cgi-bin/authLogin.cgi247
#410 /.vscode/.env247
#411 /mg.php247
#412 /sitemap_index_10.xml246
#413 /.env.old246
#414 /env.backup246
#415 /wp-config.php.bak246
#416 /api/v2/marketplace/sellers/631/products/queue246
#417 /p1u.php246
#418 /solr/admin/info/system245
#419 /laravel/core/.env245
#420 /server-info.php244
#421 /nginx/.env244
#422 /.env.stage243
#423 /sitemap_index_9.xml242
#424 /.aws/config241
#425 /sitemap_index_4.xml241
#426 /mailer/.env240
#427 /sitemap_index_8.xml240
#428 /wp-admin/edit-tags.php239
#429 /xampp/.env239
#430 /admin/config238
#431 /groups%22%22238
#432 /pesca/login/index.php237
#433 /.env.production.local237
#434 /api/shared/.env237
#435 /loja/busca.php237
#436 /sitemap_index_20.xml235
#437 /sitemap_index_25.xml235
#438 /dashboard/phpinfo.php235
#439 /app/config/parameters.yml235
#440 /sitemap_index_30.xml235
#441 /nfile.php235
#442 /api/shared/config/config.env234
#443 /node_modules/.env234
#444 /403.php233
#445 /test/wp-includes/wlwmanifest.xml232
#446 /api/shared/config/.env232
#447 /node/.env_example232
#448 /api/shared/config.env232
#449 /sitemap_index_29.xml231
#450 /sitemap_index_21.xml231
#451 /sitemap_index_13.xml231
#452 /.env_sample231
#453 /item/Caique-Brudden-Explorer-Fishing-Up-.html231
#454 /sitemap_index_28.xml230
#455 /kyc/.env230
#456 /al.php230
#457 /sitemap_index_12.xml230
#458 /wp-admin/css/colors/blue/atomlib.php229
#459 /api/config.env229
#460 /service/email_service.py228
#461 /website/.env228
#462 /administrator/index.php227
#463 /sitemap_index_26.xml227
#464 /sitemap_index_24.xml227
#465 /server_info.php227
#466 /sitemap_index_23.xml227
#467 /dashboard227
#468 /config.env226
#469 /filemanager.php226
#470 /demo226
#471 /wp-freya.php226
#472 /owa/auth.owa225
#473 /admin/server_info.php225
#474 /site225
#475 /epinyins.php225
#476 /sitemap_index_33.xml224
#477 /content.php223
#478 /wp-admin/maint223
#479 /sitemap_index_18.xml223
#480 /wp-admin/function.php223
#481 /loja/cartService.php223
#482 /secured/phpinfo.php222
#483 /wp-admin/css/colors/blue222
#484 /config/.env220
#485 /xml/images.xml220
#486 /sitemap_index_3.xml219
#487 /gold.php219
#488 /api/v2/marketplace/sellers/615/products/queue219
#489 /sitemap_index_7.xml218
#490 /sitemap_index_2.xml218
#491 /NewFile.php217
#492 /en/assets/images/logos/HTB.JPG217
#493 /gg.php217
#494 /admin/kcfinder/upload.php217
#495 /wsman216
#496 /api/v2/marketplace/sellers/631/products/batch216
#497 /sitemap_index_6.xml216
#498 /application.properties216
#499 /ff2.php216
#500 /site/wp-includes/wlwmanifest.xml214


Data was last updated on: Sep 17, 2025



Logging Research

We love logs. In this section we will share some of the data we are parsing from our logs and honeypots we have live.

Trunc Logging

Logging for fun and a good night of sleep.

  • Real time search
  • Google simple
  • Cheap
  • Just works
  • PCI compliance
Trunc Research

Latest log-based threat analysis added.

Contact us!

Do you have an idea for a research that is not here? See something wrong? Contact us at support@noc.org

Tired of price gouging
  • Clear pricing
  • No need to guess
  • Real people
  • Real logging

Simple, Affordable, Log Management and Analysis.

14 days free trial. No credit card required.