Web logs 404 analysis - past 72 hours
Dec 15, 2025
Automatically updated daily

Checking for 404 errors in your logs can reveal more than just broken links, it can also expose files and URLs that attackers are actively scanning for. To track this behavior, we set up hundreds of honeypots and analyzed live web traffic data, giving us insight into which files and URLs are being targeted across the internet.


This table bellow list the top URLs being scanned in the past 72 hours. Some of them may show what attacker are actively looking for and new vulnerabilities in the wild.


Rank Scanned URL Counter
#1 /api/v2/auth27,481
#2 /wp-login.php16,123
#3 /autodiscover/autodiscover.xml13,525
#4 /.well-known/traffic-advice8,303
#5 /index.php7,994
#6 /saiga.php7,012
#7 /rest/V1/inventory/source-items6,209
#8 /[object%20Object]5,896
#9 /.env4,765
#10 /wp-content/plugins/simple-ajax-chat/includes/sac-check-user.php3,616
#11 /admin.php2,972
#12 /autoload_classmap/function.php2,865
#13 /about.php2,709
#14 /chosen.php2,580
#15 /xmlrpc.php2,492
#16 /wp-content/video2,466
#17 /bless.php2,454
#18 /wp-json/oembed/1.0/embed2,434
#19 /upload/banner2,396
#20 /api/v2/products/22472,365
#21 /abcd.php2,291
#22 /comment-subscriptions2,262
#23 /file.php2,163
#24 /wp-good.php2,104
#25 /goods.php2,099
#26 /ioxi-o.php2,061
#27 /akcc.php1,989
#28 /classwithtostring.php1,966
#29 /mah/function.php1,933
#30 /404.php1,898
#31 /wp-blog.php1,865
#32 /edit.php1,858
#33 /new.php1,827
#34 /wp-content/plugins/admin.php1,815
#35 /wp-content/autoload_classmap.php1,801
#36 /ahax.php1,801
#37 /4041,799
#38 /.well-known/passkey-endpoints1,770
#39 /wp-admin/js/autoload_classmap.php1,747
#40 /k.php1,724
#41 /info.php1,718
#42 /mah.php1,706
#43 /adminfuns.php1,698
#44 /.git/config1,693
#45 /aa.php1,677
#46 /wp-content/themes/about.php1,670
#47 /wp-content/admin.php1,667
#48 /themes.php1,643
#49 /simple.php1,631
#50 /wp-content/admin-header.php1,605
#51 /manager.php1,605
#52 /buy.php1,603
#53 /api/v2/products/16593711941,600
#54 /gg.php1,598
#55 /api/v2/products/16593705401,596
#56 /api/v2/products/16593695921,593
#57 /api/v2/products/16593710291,592
#58 /api/v2/products/16593694851,589
#59 /sitemap.xml1,587
#60 /api/v2/products/16593720221,585
#61 /api/v2/products/16593706901,583
#62 /api/v2/products/16593701431,582
#63 /api/v2/products/16593714621,582
#64 /api/v2/products/16593705391,577
#65 /api/v2/products/16593719501,577
#66 /api/v2/products/16593718841,577
#67 /api/v2/products/16593706491,576
#68 /api/v2/products/16593697651,574
#69 /api/v2/products/16593703151,572
#70 /api/v2/products/16593714891,572
#71 /bolt.php1,570
#72 /api/v2/products/16593689751,569
#73 /api/v2/products/16593693181,568
#74 /api/v2/products/16593712171,567
#75 /api/v2/products/16593690381,566
#76 /api/v2/products/16593693661,562
#77 /api/v2/products/16593717301,560
#78 /api/v2/products/16593698631,557
#79 /api/v2/products/16593720421,556
#80 /api/v2/products/16593699411,555
#81 /api/v2/products/16593709401,553
#82 /images/install.php1,546
#83 /wp-admin/classwithtostring.php1,522
#84 /elp.php1,511
#85 /av.php1,505
#86 /submissions1,499
#87 /wp-content/themes/admin.php1,483
#88 /wp-admin/css/about.php1,454
#89 /App/__healthcheck1,402
#90 /wp-admin/includes/colour.php1,385
#91 /wp-conflg/function.php1,361
#92 /api/.env1,344
#93 /alfa.php1,344
#94 /wp-content/backups-dup-lite1,338
#95 /wp-cron.php1,302
#96 /shop1,279
#97 /radio.php1,233
#98 /backend/.env1,225
#99 /files1,203
#100 /atomlib.php1,202
#101 /wp.php1,199
#102 /app/impulse/products1,196
#103 /cong.php1,190
#104 /wp-content/plugins/pwnd/pwnd.php1,175
#105 /wp-admin1,168
#106 /admin/.env1,147
#107 /item.php1,136
#108 /dropdown.php1,126
#109 /num.php1,112
#110 /\x22https:/www.fabeestore.com.br/catalogsearch/result/index1,099
#111 /sources.php1,098
#112 /cdn-cgi/rum1,081
#113 /cgi-bin/file.php1,077
#114 /images1,056
#115 /app_dev.php/_profiler/phpinfo1,054
#116 /wp-content/plugins/pwnd/as.php1,043
#117 /.env.example1,033
#118 /browse.php1,031
#119 /wp-json/commerce/paypal/payments/payment-token997
#120 /wp-content/languages/index.php991
#121 /wp-json/commerce/paypal/payments/start-trial979
#122 /wp-json/commerce/paypal/payments/order974
#123 /assets/images933
#124 /wp-json/commerce/paypal/payments/confirm931
#125 /null924
#126 /api/sessions922
#127 /wp-admin/wp-admins.php919
#128 /wp-admin/css/colors/blue/atomlib.php897
#129 /wp-admin/index.php879
#130 /txets.php869
#131 /wp-user.php855
#132 /1.php855
#133 /wp-admin/css854
#134 /wp-signin.php853
#135 /content.php834
#136 /contrato/wap/crons/enviar-email.php812
#137 /backup793
#138 /mini790
#139 /AutoDiscover/autodiscover.xml770
#140 /filter769
#141 /wp-content/index.php762
#142 /admin762
#143 /wp-json/commerce/paypal/payments/cancel758
#144 /style.php753
#145 /pagamento/mercadopago/ipn.php719
#146 /wp-admin/images/index.php719
#147 /wp-content/languages718
#148 /wp-includes/wlwmanifest.xml714
#149 /demo/equipe/api/v2/auth689
#150 /wp-admin/js688
#151 /api/v1/5331de46da1425c8b5f036d69da64571/json/desconto-url/dados-xml677
#152 /en/AutoDiscover/autodiscover.xml676
#153 /test.php672
#154 /admin/config.php659
#155 /wp-admin/includes/index.php652
#156 /tytyd.php646
#157 /wp-admin/js/widgets640
#158 /wp-content/uploads636
#159 /inputs.php636
#160 /wp-content/upgrade/index.php624
#161 /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php621
#162 /administrator616
#163 /wp-admin/css/colors/blue615
#164 /web/wp-includes/wlwmanifest.xml602
#165 /wordpress/wp-includes/wlwmanifest.xml600
#166 /wp/wp-includes/wlwmanifest.xml598
#167 /wp-includes/IXR595
#168 /wp-content/uploads/2025591
#169 /sitemap_index.xml586
#170 /web_api/auth583
#171 /cgi-bin580
#172 /index/function.php578
#173 /play/aula/conteudo/buscar/48271642577
#174 /api/v2/marketplace/sellers/376/products/status-batch576
#175 /api/v2/marketplace/sellers/376/products/price-batch576
#176 /2019/wp-includes/wlwmanifest.xml575
#177 /api/v2/marketplace/sellers/376/products/stock-batch575
#178 /login570
#179 /shop/wp-includes/wlwmanifest.xml568
#180 /blog/wp-includes/wlwmanifest.xml565
#181 /apps564
#182 /feed563
#183 /xmrlpc.php563
#184 /wp-admin/network/admin.php554
#185 /api/actions552
#186 /api/v2/brands/4718550
#187 /ccstore/v1/registry549
#188 /api/action543
#189 /install.php543
#190 /website/wp-includes/wlwmanifest.xml540
#191 /wp-content/style.php535
#192 /wp-includes/block-bindings534
#193 /news/wp-includes/wlwmanifest.xml532
#194 /wp-content/themes/twentytwentytwo/index.php531
#195 /cc.php530
#196 /api/v2/customers/login528
#197 /_next/data526
#198 /wp-editor.php525
#199 /+CSCOL+/a1.jar514
#200 /rest/V1/orders512
#201 /+CSCOL+/Java.jar512
#202 /file5.php504
#203 /cgi-bin/index.php490
#204 /wp-plain.php489
#205 /wp-includes/customize/chosen.php487
#206 /wp-includes/sitemaps/autoload_classmap.php478
#207 /.well-known/acme-challenge/file.php475
#208 /wp-admin/js/index.php474
#209 /lowpr.php469
#210 /function/function.php466
#211 /mini.php461
#212 /public/files/index.php460
#213 /public/wp-content/index.php459
#214 /Sanskrit.php459
#215 /public/files451
#216 /umbro/masculino449
#217 /wp-includes/rest-api/fields447
#218 /assets/as.php446
#219 /public/wp-content445
#220 /api/v2/batch/1145445
#221 /.well-known/apple-app-site-association444
#222 /loja/catalogo.php442
#223 /wp-includes/images442
#224 /api/v2/products/1659370661440
#225 /wp-content/themes439
#226 /api/v2/batch/1146439
#227 /play/aula/conteudo/buscar/75016992438
#228 /en/autodiscover/autodiscover.xml437
#229 /fr433
#230 /css/install.php428
#231 /graphql426
#232 /wp-includes/ID3424
#233 /api/v2/products/531424
#234 /2018/wp-includes/wlwmanifest.xml424
#235 /wp-includes/js/dist/development422
#236 /network.php417
#237 /umbro416
#238 /wp-content/plugins/fix/up.php415
#239 /moon.php411
#240 /images/admin.php411
#241 /.env.prod410
#242 /api/v2/marketplace/sellers/655/products/queue410
#243 /options-reading.php410
#244 /4ec82611408
#245 /wp-content/plugins/hellopress/wp_filemanager.php407
#246 /api/v2/marketplace/sellers/425/products/queue406
#247 /api/v2/marketplace/sellers/537/products/queue406
#248 /wp-includes/Text405
#249 /pb405
#250 /.well-known/index.php405
#251 /api/v2/batch/1185403
#252 /api/v2/batch/1190402
#253 /api/v2/batch/1188402
#254 /api/v2/batch/1186402
#255 /api/v2/batch/1176402
#256 /api/v2/batch/1182402
#257 /api/v2/batch/1181402
#258 /api/v2/batch/1219401
#259 /api/v2/batch/1218401
#260 /api/v2/batch/1177401
#261 /api/v2/batch/1173401
#262 /pinfo.php401
#263 /wp-includes/Text/Diff/Engine400
#264 /api/v2/batch/1187400
#265 /api/v2/batch/1184400
#266 /api/v2/batch/1171400
#267 /api/v2/batch/1198400
#268 /api/v2/batch/1192400
#269 /api/v2/batch/1189400
#270 /api/v2/batch/1183400
#271 /api/v2/batch/1179400
#272 /api/v2/batch/1170400
#273 /api/v2/batch/1214399
#274 /api/v2/batch/1194399
#275 /api/v2/batch/1193399
#276 /api/v2/batch/1178399
#277 /rest/V1/store/storeViews398
#278 /api/v2/batch/1174398
#279 /api/v2/batch/1169398
#280 /api/v2/batch/1191397
#281 /api/v2/batch/1175397
#282 /api/v2/batch/1172397
#283 /api/v2/batch/1168397
#284 /wp-admin/css/colors/ocean/about.php396
#285 /uploads393
#286 /api/v2/batch/1165392
#287 /api392
#288 /wp-content/classwithtostring.php392
#289 /settings/.env391
#290 /html/.env390
#291 /wp-content/plugins/cartflows/assets/fonts389
#292 /api/v2/batch/1166386
#293 /wp-content/edit.php384
#294 /api/v2/batch/1142383
#295 /wp-includes/js/dist378
#296 /wp-content/themes/twentytwentyfour/system_cache.php378
#297 /phpinfo377
#298 /wp-content/themes/pridmag/install.php375
#299 /wp-content/themes/tflow/as.php374
#300 /api/v2/marketplace/rebates/queue372
#301 /aws.yml371
#302 /_profiler/phpinfo371
#303 /.well-known/acme-challenge/wp-login.php369
#304 /www.php368
#305 /wp-includes/assets/autoload_classmap.php363
#306 /wordpress362
#307 /umbro/feminino361
#308 /wp-includes/style-engine/autoload_classmap.php358
#309 /api/graphql358
#310 /wp-includes/theme-compat357
#311 /api/v2/marketplace/sellers/queue357
#312 /wp-includes/style-engine/wp-conflg.php356
#313 /wp-includes/index.php355
#314 /wp-includes/block-supports354
#315 /pilatesgratuito354
#316 /wp-includes/SimplePie/autoload_classmap.php352
#317 /assets/images/accesson.php350
#318 /wp-includes/css/autoload_classmap.php348
#319 /sitemap-index.xml345
#320 /404testpage4525d2fdc344
#321 /loja/busca.php343
#322 /apis/.env342
#323 /wp342
#324 /natal340
#325 /api/gql337
#326 /old334
#327 /shell.php333
#328 /stage/.env332
#329 /wp-links-opml.php330
#330 /configura/aws_settings.php329
#331 /.well-known/acme-challenge/cloud.php327
#332 /wp-content/themes/twentytwentytwo327
#333 /simular325
#334 /test324
#335 /auth/.env321
#336 /ccstore/v1/images321
#337 /wp-includes/ID3/simi.php318
#338 /debug/default/view318
#339 /backup/aws-credentials.bak317
#340 /my-account/login313
#341 /api/v1/677e09724f0e2df9b6c000b75b5da10d/conectala/freight310
#342 /wp-includes/js/jquery/jquery.php309
#343 /v2/_catalog307
#344 /papelariafofa305
#345 /wp-includes/SimplePie/index.php305
#346 /sso/ifood/play/player/6305193305
#347 /dev/.env.development.local304
#348 /includes.php304
#349 /wp-includes/js/crop304
#350 /wp-includes/PHPMailer/index.php304
#351 /rest/V1/products/special-price303
#352 /rest/V1/products/base-prices303
#353 /new299
#354 /graphql/api299
#355 /wp-json/commerce/paypal/payments/cards299
#356 /comment.php298
#357 /api/v2/marketplace/sellers/487/products/queue295
#358 /api/v2/marketplace/sellers/471/products/queue295
#359 /api/v2/marketplace/sellers/354/products/queue295
#360 /wp1/wp-includes/wlwmanifest.xml295
#361 /api/v2/marketplace/sellers/473/products/queue294
#362 /api/v2/marketplace/sellers/476/products/queue294
#363 /api/v2/marketplace/sellers/363/products/queue294
#364 /api/v2/marketplace/sellers/360/products/queue294
#365 /api/v2/marketplace/sellers/536/products/queue294
#366 /api/v2/marketplace/sellers/533/products/queue294
#367 /api/v2/marketplace/sellers/423/products/queue294
#368 /api/v2/marketplace/sellers/364/products/queue294
#369 /wp-admin/autoload_classmap.php293
#370 /minha-conta/pedidoapi/v2/front/checkout/cart293
#371 /api/v2/marketplace/sellers/430/products/queue293
#372 /api/v2/marketplace/sellers/534/products/queue293
#373 /api/v2/marketplace/sellers/463/products/queue292
#374 /api/v2/marketplace/sellers/351/products/queue292
#375 /wp-includes/Text/autoload_classmap.php291
#376 /api/v2/marketplace/sellers/391/products/queue291
#377 /api/v2/marketplace/sellers/455/products/queue291
#378 /api/v2/marketplace/sellers/388/products/queue291
#379 /api/v2/marketplace/sellers/31/products/queue291
#380 /api/v2/marketplace/sellers/457/products/queue291
#381 /config/aws-credentials.php290
#382 /about290
#383 /wp-includes/html-api/index.php289
#384 /css.php289
#385 /wp-includes/pomo/index.php287
#386 /api/v2/marketplace/sellers/390/products/queue285
#387 /customer/account/create285
#388 /platform/.env283
#389 /config.php283
#390 /wp-content/uploads/env.php280
#391 /.env.development280
#392 /catalogsearch/result279
#393 /telescope/requests278
#394 /server-status276
#395 /.aws/credentials274
#396 /blog273
#397 /frontend/.env273
#398 /.config/.env.example.local272
#399 /flower.php270
#400 /HNAP1267
#401 /wp-content/themes/seotheme/db.php266
#402 /wp-content/txets.php265
#403 /-/-/-/-/-/-/-/-/-/-265
#404 /wp-includes/bk/index.php263
#405 /file4.php262
#406 /wp-content/uploads/index.php260
#407 /mail.php260
#408 /wp-content/plugins/elementor/assets/lib/font-awesome/webfonts260
#409 /api/v2/marketplace/sellers/615/products/queue259
#410 /konfig/aws-credentials.php258
#411 /api/v2/batch/1128258
#412 /wp-includes/blocks/code257
#413 /SistemaEAD_CPREM/login/index.php256
#414 /api/v2/batch/1120256
#415 /api/v2/batch/1117256
#416 /api/v2/batch/1121256
#417 /api/v2/batch/1126256
#418 /.well-known256
#419 /bin256
#420 /api/v2/batch/1148255
#421 /api/v2/batch/1127255
#422 /api/v2/batch/1115255
#423 /api/v2/batch/1129254
#424 /api/v2/batch/1125254
#425 /api/v2/batch/1149254
#426 /autoload_classmap.php254
#427 /api/v2/batch/1124253
#428 /api/v2/batch/1116252
#429 /api/v2/batch/1113252
#430 /appWP/lab/wp-admin/css/colors/blue/blue.php251
#431 /api/v2/batch/1118251
#432 /api/v2/batch/1114251
#433 /wp-includes/certificates250
#434 /api/v2/batch/1119250
#435 /test/wp-includes/wlwmanifest.xml249
#436 /class-t.api.php249
#437 /pesca/login/index.php248
#438 /css248
#439 /wp-admin/txets.php247
#440 /api/v2/products/386246
#441 /api/v2/batch/1111246
#442 /api/v2/batch/1110246
#443 /fm.php245
#444 /lock360.php244
#445 /api/v1/ede49134002f41b1320469a869921657/json/pedido/atualizacoes243
#446 /api/v1/7d7f91c7b727f4627bf81883ea25a347/json/pedido/atualizacoes243
#447 /api/v2/3f0803957c6b00580c1d83ddef8033ca/json/pedido/atualizacoes243
#448 /api/v1/5331de46da1425c8b5f036d69da64571/json/pedido/atualizacoes240
#449 /postnews.php240
#450 /zwso.php237
#451 /loja/cartService.php236
#452 /dashboard/.env.credentials235
#453 /.git/credentials232
#454 /uploads/index.php230
#455 /gifclass.php229
#456 /wp-includes/rest-api227
#457 /docker/.env225
#458 /simular-credito-trabalhador224
#459 /docs/wp-login.php224
#460 /wp-includes/Text/Diff/Renderer/index.php223
#461 /public/.env223
#462 /portal/.env222
#463 /instance/aws_credentials.py221
#464 /api/v2/3f0803957c6b00580c1d83ddef8033ca/json/produto/atualizacoes221
#465 /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application221
#466 /api/v1/ede49134002f41b1320469a869921657/json/produto/atualizacoes220
#467 /api/v1/7d7f91c7b727f4627bf81883ea25a347/json/produto/atualizacoes220
#468 /m.php220
#469 /files.php220
#470 /api/v1/5331de46da1425c8b5f036d69da64571/json/produto/atualizacoes219
#471 /file2.php219
#472 /cms/wp-includes/wlwmanifest.xml218
#473 /site/wp-includes/wlwmanifest.xml218
#474 /lv.php217
#475 /stag/.env215
#476 /software214
#477 /public_html/.env214
#478 /css/index.php211
#479 /app/config/parameters.yml211
#480 /wp-admin/includes/themes.php210
#481 /RDWeb/Pages210
#482 /module/ngmercadolivre/notificacao209
#483 /wp-includes/js/codemirror/index.php209
#484 /wp-content/themes/twentytwentythree/patterns/index.php208
#485 /app/.env208
#486 /rest/V1/products207
#487 /wp-includes/Requests/index.php207
#488 /login.action204
#489 /project/.env204
#490 /api/v2/marketplace/sellers/655/orders/queue203
#491 /api/v2/batch/162620203
#492 /api/v2/batch/162619203
#493 /api/v2/batch/162570203
#494 /api/v2/batch/162569203
#495 /api/v2/batch/162562203
#496 /api/v2/batch/162560203
#497 /api/v2/batch/162547203
#498 /api/v2/batch/162546203
#499 /api/v2/batch/162545203
#500 /api/v2/batch/162531203


Data was last updated on: Dec 15, 2025



Logging Research

We love logs. In this section we will share some of the data we are parsing from our logs and honeypots we have live.

Trunc Logging

Logging for fun and a good night of sleep.

  • Real time search
  • Google simple
  • Cheap
  • Just works
  • PCI compliance
Trunc Research

Latest log-based threat analysis added.

Contact us!

Do you have an idea for a research that is not here? See something wrong? Contact us at support@noc.org

Tired of price gouging
  • Clear pricing
  • No need to guess
  • Real people
  • Real logging

Simple, Affordable, Log Management and Analysis.

14 days free trial. No credit card required.