Checking for 404 errors in your logs can reveal more than just broken links, it can also expose files and URLs that attackers are actively scanning for. To track this behavior, we set up hundreds of honeypots and analyzed live web traffic data, giving us insight into which files and URLs are being targeted across the internet.
This table bellow list the top URLs being scanned in the past 72 hours. Some of them may show what attacker are actively looking for and new vulnerabilities in the wild.
Rank | Scanned URL | Counter |
---|---|---|
#1 | /wp-login.php | 30,016 |
#2 | /xmlrpc.php | 7,678 |
#3 | /wp-json/oembed/1.0/embed | 7,504 |
#4 | /sitemap.xml | 6,133 |
#5 | /.env | 5,355 |
#6 | /module/ngmercadolivre/notificacao | 4,552 |
#7 | /wp-cron.php | 3,064 |
#8 | /api/v2/categories/64 | 3,041 |
#9 | /.git/config | 3,011 |
#10 | /.well-known/traffic-advice | 2,834 |
#11 | /file.php | 2,635 |
#12 | /api/v2/categories/65 | 2,549 |
#13 | /index.php | 2,356 |
#14 | /rest/V1/store/storeViews | 2,268 |
#15 | /404 | 2,226 |
#16 | /search | 2,010 |
#17 | /info.php | 1,992 |
#18 | /chosen.php | 1,944 |
#19 | /en/AutoDiscover/autodiscover.xml | 1,790 |
#20 | /api/v3/community | 1,761 |
#21 | /wordpress | 1,755 |
#22 | /wp | 1,591 |
#23 | /old | 1,585 |
#24 | /backup | 1,564 |
#25 | /main | 1,534 |
#26 | /pagamento/mercadopago/ipn.php | 1,517 |
#27 | /atomlib.php | 1,485 |
#28 | /bk | 1,468 |
#29 | /bc | 1,460 |
#30 | /new | 1,446 |
#31 | /admin.php | 1,405 |
#32 | /wp-admin | 1,402 |
#33 | /wp-content/plugins/fix/up.php | 1,400 |
#34 | /style.php | 1,385 |
#35 | /.well-known/nodeinfo | 1,334 |
#36 | /goat.php | 1,331 |
#37 | /file2.php | 1,327 |
#38 | /lock360.php | 1,304 |
#39 | /about.php | 1,303 |
#40 | /login | 1,279 |
#41 | /aa.php | 1,259 |
#42 | /wp-includes/wlwmanifest.xml | 1,239 |
#43 | /autoload_classmap.php | 1,239 |
#44 | /en/autodiscover/autodiscover.xml | 1,231 |
#45 | /akc.php | 1,186 |
#46 | /contact | 1,161 |
#47 | /alfa.php | 1,159 |
#48 | /makeasmtp.php | 1,155 |
#49 | /contact-us | 1,136 |
#50 | /manager/html | 1,129 |
#51 | /test | 1,124 |
#52 | /contato.html | 1,108 |
#53 | /ioxi-o.php | 1,107 |
#54 | /HNAP1 | 1,106 |
#55 | /wp-content/plugins/hellopress/wp_filemanager.php | 1,105 |
#56 | /flower.php | 1,100 |
#57 | /classwithtostring.php | 1,098 |
#58 | /wp.php | 1,090 |
#59 | /contatos.html | 1,089 |
#60 | /faleconosco | 1,082 |
#61 | /cong.php | 1,070 |
#62 | /contatos | 1,069 |
#63 | /server-status | 1,068 |
#64 | /goods.php | 1,059 |
#65 | /fale-conosco | 1,053 |
#66 | /web/wp-includes/wlwmanifest.xml | 1,041 |
#67 | /contate | 1,035 |
#68 | /wordpress/wp-includes/wlwmanifest.xml | 1,032 |
#69 | /wp-admin/images/moon.php | 1,030 |
#70 | /telescope/requests | 1,028 |
#71 | /contate-nos | 1,027 |
#72 | /.well-known/acme-challenge/about.php | 1,026 |
#73 | /wp/wp-includes/wlwmanifest.xml | 1,023 |
#74 | /api/v2/categories/86 | 1,023 |
#75 | /404testpage4525d2fdc | 1,012 |
#76 | /nc4.php | 991 |
#77 | /autoload_classmap/function.php | 991 |
#78 | /wp-content/plugins/wpterm.php | 990 |
#79 | /2019/wp-includes/wlwmanifest.xml | 984 |
#80 | /wp-content/style.php | 981 |
#81 | /blog/wp-includes/wlwmanifest.xml | 977 |
#82 | /home | 974 |
#83 | /shop/wp-includes/wlwmanifest.xml | 974 |
#84 | /website/wp-includes/wlwmanifest.xml | 974 |
#85 | /suporte | 965 |
#86 | /news/wp-includes/wlwmanifest.xml | 961 |
#87 | /v2/_catalog | 960 |
#88 | /admin | 952 |
#89 | /contato | 943 |
#90 | /debug/default/view | 933 |
#91 | /_profiler/phpinfo | 933 |
#92 | /edit.php | 910 |
#93 | /loja/catalogo.php | 907 |
#94 | /buy.php | 889 |
#95 | /wp-admin/setup-config.php | 881 |
#96 | /asasx.php | 866 |
#97 | /users.php | 865 |
#98 | /tinyfilemanager.php | 859 |
#99 | /w.php | 850 |
#100 | /mm.php | 846 |
#101 | /wp-admin/css | 815 |
#102 | /.well-known/apple-app-site-association | 812 |
#103 | /CLA.php | 806 |
#104 | /wsa.php | 797 |
#105 | /wp-setup.php | 780 |
#106 | /wp-content/wp-conflg.php | 769 |
#107 | /wp-api.php | 769 |
#108 | /login.action | 761 |
#109 | /images/images/cache.php | 756 |
#110 | /wp-sitemap.xml | 756 |
#111 | /wp-admin/style.php | 755 |
#112 | /test.php | 750 |
#113 | /phpinfo | 741 |
#114 | /about | 733 |
#115 | /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application | 728 |
#116 | /.well-known/acme-challenge/muse.php | 725 |
#117 | /@vite/env | 722 |
#118 | /server | 718 |
#119 | /_all_dbs | 718 |
#120 | /wp-includes/fonts/admin.php | 718 |
#121 | /wp-includes/IXR/autoload_classmap.php | 711 |
#122 | /wp-plain.php | 701 |
#123 | /actuator/env | 697 |
#124 | /public/.env | 692 |
#125 | /dynip/f282640c | 685 |
#126 | /wp-content/index.php | 666 |
#127 | /api/.env | 658 |
#128 | /gecko.php | 654 |
#129 | /core/.env | 653 |
#130 | /Form | 644 |
#131 | /07550e18 | 631 |
#132 | /wp-admin/js/index.php | 626 |
#133 | /loja/login_layout.php | 622 |
#134 | /cool.php | 621 |
#135 | /222.php | 599 |
#136 | /laravel/.env | 598 |
#137 | /cgi-bin/luci/;stok=/locale | 587 |
#138 | /app/.env | 582 |
#139 | /wp-admin/css/colors/blue/index.php | 581 |
#140 | /administrator | 580 |
#141 | /2018/wp-includes/wlwmanifest.xml | 577 |
#142 | /wp-content/themes/style.php | 563 |
#143 | /.well-known/acme-challenge/cloud.php | 562 |
#144 | /1.php | 557 |
#145 | /13.php | 555 |
#146 | /des.php | 552 |
#147 | /sites/all/libraries/kcfinder/upload.php | 541 |
#148 | /s/1313e2236313e20373e2538313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties | 541 |
#149 | /.git/index | 535 |
#150 | /wp-includes/fonts/index.php | 532 |
#151 | /index.html | 527 |
#152 | /web | 520 |
#153 | /web/.env | 518 |
#154 | /user/login | 517 |
#155 | /.well-known/passkey-endpoints | 517 |
#156 | /lv.php | 516 |
#157 | /manager.php | 515 |
#158 | /ava.php | 512 |
#159 | /phpinfo.php | 508 |
#160 | /dropdown.php | 507 |
#161 | /-/-/-/-/-/-/-/-/-/- | 507 |
#162 | /ffile.php | 505 |
#163 | /gfile.php | 504 |
#164 | /sdk | 495 |
#165 | /evox/about | 493 |
#166 | /inputs.php | 493 |
#167 | /admin/.env | 491 |
#168 | /backend/.env | 489 |
#169 | /we.php | 476 |
#170 | /.env.example | 469 |
#171 | /axx.php | 469 |
#172 | /wp-editor.php | 457 |
#173 | /bolt.php | 451 |
#174 | /assets/plugins/kcfinder/upload.php | 450 |
#175 | /pb | 449 |
#176 | /gmo.php | 449 |
#177 | /as.php | 443 |
#178 | /default.php | 434 |
#179 | /2020/wp-includes/wlwmanifest.xml | 433 |
#180 | /site/.env | 430 |
#181 | /asset/kcfinder/upload.php | 429 |
#182 | /prod/.env | 428 |
#183 | /files | 427 |
#184 | /.env.bak | 422 |
#185 | /file5.php | 421 |
#186 | /error.php | 415 |
#187 | /rsnu.php | 415 |
#188 | /rest/V1/orders | 413 |
#189 | /3.php | 413 |
#190 | /uploads | 412 |
#191 | /index.php/api/soap | 412 |
#192 | /assets/kcfinder/upload.php | 412 |
#193 | /pp.php | 410 |
#194 | /api | 409 |
#195 | /kcfinder/upload.php | 409 |
#196 | /js/kcfinder/upload.php | 409 |
#197 | /images | 408 |
#198 | /admin/controller/extension/extension | 406 |
#199 | /cfile.php | 405 |
#200 | /dev/.env | 404 |
#201 | /simple.php | 404 |
#202 | /file1.php | 401 |
#203 | /assets/js/kcfinder/upload.php | 401 |
#204 | /sites/default/files | 400 |
#205 | /local/.env | 399 |
#206 | /api/v2/customers/login | 399 |
#207 | /abcd.php | 397 |
#208 | /file17.php | 397 |
#209 | /.well-known/web-identity | 397 |
#210 | /f35.php | 393 |
#211 | /.well-known/webauthn | 393 |
#212 | /.well-known/change-password | 393 |
#213 | /wp-content/themes/seotheme/db.php | 392 |
#214 | /contrato/wap/crons/enviar-email.php | 392 |
#215 | /plugins/kcfinder/upload.php | 391 |
#216 | /.well-known/resource-that-should-not-exist-whose-status-code-should-not-be-200 | 391 |
#217 | /database/.env | 389 |
#218 | /feed/mnpodcast | 389 |
#219 | /ckeditor/plugins/kcfinder/upload.php | 389 |
#220 | /admin/index.php | 385 |
#221 | /cms | 384 |
#222 | /.well-known/acme-challenge/xmrlpc.php | 383 |
#223 | /application/.env | 382 |
#224 | /js/tinymce/kcfinder/upload.php | 380 |
#225 | /php.php | 376 |
#226 | /lib/kcfinder/upload.php | 376 |
#227 | /api/v2/freights/316 | 374 |
#228 | /admin/config.php | 374 |
#229 | /yasnu.php | 373 |
#230 | /form.html | 372 |
#231 | /ioxi2.php | 371 |
#232 | /cc.php | 370 |
#233 | /yanki.php | 370 |
#234 | /gm.php | 370 |
#235 | /fe5.php | 370 |
#236 | /apiundefined | 370 |
#237 | /ckeditor/kcfinder/upload.php | 366 |
#238 | /wordpress/wp-admin/setup-config.php | 362 |
#239 | /blog | 360 |
#240 | /cron/.env | 359 |
#241 | /member-signup | 357 |
#242 | /upl.php | 356 |
#243 | /t4 | 356 |
#244 | /new/.env | 355 |
#245 | /password.php | 355 |
#246 | /systembc/password.php | 355 |
#247 | /geoip | 355 |
#248 | /ola-mundo | 355 |
#249 | /new4.php | 353 |
#250 | /php_info.php | 352 |
#251 | /wp-admin/js | 350 |
#252 | /a2.php | 350 |
#253 | /shell1.php | 350 |
#254 | /class.1.php | 350 |
#255 | /jmfi2.php | 350 |
#256 | /doc.php | 348 |
#257 | /gfile1.php | 348 |
#258 | /cache.php | 347 |
#259 | /_phpinfo.php | 346 |
#260 | /www/.env | 343 |
#261 | /mar.php | 343 |
#262 | /js/.env | 342 |
#263 | /resp.php | 342 |
#264 | /apps/.env | 340 |
#265 | /wp1/wp-includes/wlwmanifest.xml | 340 |
#266 | /shell.php | 338 |
#267 | /wiki | 338 |
#268 | /file7.php | 338 |
#269 | /444.php | 337 |
#270 | /main/.env | 336 |
#271 | /docker/.env | 334 |
#272 | /env/.env | 334 |
#273 | /g1.php | 333 |
#274 | /awstats/.env | 331 |
#275 | /crm/.env | 327 |
#276 | /mail/.env | 326 |
#277 | /not_found | 324 |
#278 | /k.php | 322 |
#279 | /file4.php | 320 |
#280 | /ext.php | 318 |
#281 | /development/.env | 317 |
#282 | /css.php | 317 |
#283 | /wp-update.php | 317 |
#284 | /www.ifs.se/about-ifs/ifs-policies/ifs-cookie-policy.html | 317 |
#285 | /.env.prod | 316 |
#286 | /config/aws.yml | 312 |
#287 | /aws.yml | 311 |
#288 | /old-application-forms | 311 |
#289 | /noc-cdn | 309 |
#290 | /www.ifs.se/about-ifs | 309 |
#291 | /checkout/cart/add | 308 |
#292 | /file88.php | 308 |
#293 | /Website | 308 |
#294 | /www.esipps-int.org | 308 |
#295 | /Math.PI*180 | 307 |
#296 | /ifs-grantees/the-comstech | 307 |
#297 | /file9.php | 306 |
#298 | /file3.php | 306 |
#299 | /file6.php | 306 |
#300 | /programme | 306 |
#301 | /new.php | 305 |
#302 | /assets/components/resources/assets/components/resources/PIE.htc | 305 |
#303 | /loja/carrinho.php | 304 |
#304 | /s*,s* | 304 |
#305 | /www.ifs.se | 304 |
#306 | /031.php | 303 |
#307 | /filesss.php | 303 |
#308 | /www.neotropico.net | 303 |
#309 | /usep.php | 302 |
#310 | /dfre.php | 302 |
#311 | /ilex.php | 302 |
#312 | /vast.php | 302 |
#313 | /cccc.php | 302 |
#314 | /eauu.php | 302 |
#315 | /fs.php | 302 |
#316 | /keu.php | 302 |
#317 | /file13.php | 302 |
#318 | /file32.php | 302 |
#319 | /y.php | 301 |
#320 | /hexx.php | 301 |
#321 | /lala.php | 301 |
#322 | /520.php | 301 |
#323 | /file18.php | 301 |
#324 | /efile.php | 301 |
#325 | /SistemaEAD_CPREM/login/index.php | 300 |
#326 | /.aws/credentials | 300 |
#327 | /an.php | 299 |
#328 | /autoria-e-traducao-das-letras-dos-hinos-do-hpd-1/conteudo.php | 298 |
#329 | /num.php | 298 |
#330 | /version | 295 |
#331 | /wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot | 294 |
#332 | /moon.php | 288 |
#333 | /sitemap_index_16.xml | 287 |
#334 | /ab2h | 287 |
#335 | /ab2g | 287 |
#336 | /contacts.php | 287 |
#337 | /akcc.php | 286 |
#338 | /teorema505 | 286 |
#339 | /alive.php | 286 |
#340 | /status.php | 284 |
#341 | /tox.php | 283 |
#342 | /boaform/admin/formLogin | 282 |
#343 | /remote/login | 279 |
#344 | /gifclass.php | 278 |
#345 | /radio.php | 278 |
#346 | /files.php | 278 |
#347 | /app_dev.php/_profiler/phpinfo | 277 |
#348 | /.git/HEAD | 277 |
#349 | /333.php | 274 |
#350 | /query | 273 |
#351 | /wp-control.php | 273 |
#352 | /vendor/.env | 271 |
#353 | /portal/.env | 271 |
#354 | /aa17.php | 269 |
#355 | /hk.php | 269 |
#356 | /solr/admin/cores | 268 |
#357 | /sitemap_index_14.xml | 268 |
#358 | /sitemap_index.xml | 267 |
#359 | /667.php | 265 |
#360 | /conf/.env | 264 |
#361 | /.well-known | 263 |
#362 | /classsmtps.php | 263 |
#363 | /wp-content | 262 |
#364 | /ervin-cordero/track/single | 262 |
#365 | /zeal.php | 262 |
#366 | /sitemap_index_15.xml | 261 |
#367 | /wp-admin/autoload_classmap.php | 261 |
#368 | /wp-json/wp | 261 |
#369 | /sitemap_index_1.xml | 260 |
#370 | /new/.env.local | 260 |
#371 | /ssss.php | 260 |
#372 | /_profiler/phpinfo/info.php | 260 |
#373 | /aws-secret.yaml | 260 |
#374 | /.env.local | 259 |
#375 | /sitemap_index_27.xml | 259 |
#376 | /server-info | 259 |
#377 | /a.php | 259 |
#378 | /g.php | 259 |
#379 | /storage/.env | 258 |
#380 | /nope.php | 258 |
#381 | /wp-json/oembed | 258 |
#382 | /wp-content/themes/about.php | 257 |
#383 | /sitemap_index_5.xml | 257 |
#384 | /sitemap_index_19.xml | 257 |
#385 | /new/.env.staging | 256 |
#386 | /sendgrid.env | 256 |
#387 | /_profiler/phpinfo/phpinfo.php | 255 |
#388 | /lc.php | 255 |
#389 | /backend | 254 |
#390 | /sitemap_index_11.xml | 254 |
#391 | /stalker_portal/server/tools/auth_simple.php | 254 |
#392 | /en/.env | 252 |
#393 | /laravel/info.php | 252 |
#394 | /new/.env.production | 252 |
#395 | /lara/info.php | 252 |
#396 | /sitemap_index_32.xml | 252 |
#397 | /elf.php | 252 |
#398 | /feed | 251 |
#399 | /wp-config | 251 |
#400 | /panel | 251 |
#401 | /xampp/phpinfo.php | 249 |
#402 | /lara/phpinfo.php | 249 |
#403 | /settings.py | 249 |
#404 | /sitemap_index_0.xml | 249 |
#405 | /sitemap_index_31.xml | 248 |
#406 | /sitemap_index_17.xml | 248 |
#407 | /docker/app/.env | 248 |
#408 | /loja/arquivos/1049375/sitemaps/sitemap_1.xml | 248 |
#409 | /cgi-bin/authLogin.cgi | 247 |
#410 | /.vscode/.env | 247 |
#411 | /mg.php | 247 |
#412 | /sitemap_index_10.xml | 246 |
#413 | /.env.old | 246 |
#414 | /env.backup | 246 |
#415 | /wp-config.php.bak | 246 |
#416 | /api/v2/marketplace/sellers/631/products/queue | 246 |
#417 | /p1u.php | 246 |
#418 | /solr/admin/info/system | 245 |
#419 | /laravel/core/.env | 245 |
#420 | /server-info.php | 244 |
#421 | /nginx/.env | 244 |
#422 | /.env.stage | 243 |
#423 | /sitemap_index_9.xml | 242 |
#424 | /.aws/config | 241 |
#425 | /sitemap_index_4.xml | 241 |
#426 | /mailer/.env | 240 |
#427 | /sitemap_index_8.xml | 240 |
#428 | /wp-admin/edit-tags.php | 239 |
#429 | /xampp/.env | 239 |
#430 | /admin/config | 238 |
#431 | /groups%22%22 | 238 |
#432 | /pesca/login/index.php | 237 |
#433 | /.env.production.local | 237 |
#434 | /api/shared/.env | 237 |
#435 | /loja/busca.php | 237 |
#436 | /sitemap_index_20.xml | 235 |
#437 | /sitemap_index_25.xml | 235 |
#438 | /dashboard/phpinfo.php | 235 |
#439 | /app/config/parameters.yml | 235 |
#440 | /sitemap_index_30.xml | 235 |
#441 | /nfile.php | 235 |
#442 | /api/shared/config/config.env | 234 |
#443 | /node_modules/.env | 234 |
#444 | /403.php | 233 |
#445 | /test/wp-includes/wlwmanifest.xml | 232 |
#446 | /api/shared/config/.env | 232 |
#447 | /node/.env_example | 232 |
#448 | /api/shared/config.env | 232 |
#449 | /sitemap_index_29.xml | 231 |
#450 | /sitemap_index_21.xml | 231 |
#451 | /sitemap_index_13.xml | 231 |
#452 | /.env_sample | 231 |
#453 | /item/Caique-Brudden-Explorer-Fishing-Up-.html | 231 |
#454 | /sitemap_index_28.xml | 230 |
#455 | /kyc/.env | 230 |
#456 | /al.php | 230 |
#457 | /sitemap_index_12.xml | 230 |
#458 | /wp-admin/css/colors/blue/atomlib.php | 229 |
#459 | /api/config.env | 229 |
#460 | /service/email_service.py | 228 |
#461 | /website/.env | 228 |
#462 | /administrator/index.php | 227 |
#463 | /sitemap_index_26.xml | 227 |
#464 | /sitemap_index_24.xml | 227 |
#465 | /server_info.php | 227 |
#466 | /sitemap_index_23.xml | 227 |
#467 | /dashboard | 227 |
#468 | /config.env | 226 |
#469 | /filemanager.php | 226 |
#470 | /demo | 226 |
#471 | /wp-freya.php | 226 |
#472 | /owa/auth.owa | 225 |
#473 | /admin/server_info.php | 225 |
#474 | /site | 225 |
#475 | /epinyins.php | 225 |
#476 | /sitemap_index_33.xml | 224 |
#477 | /content.php | 223 |
#478 | /wp-admin/maint | 223 |
#479 | /sitemap_index_18.xml | 223 |
#480 | /wp-admin/function.php | 223 |
#481 | /loja/cartService.php | 223 |
#482 | /secured/phpinfo.php | 222 |
#483 | /wp-admin/css/colors/blue | 222 |
#484 | /config/.env | 220 |
#485 | /xml/images.xml | 220 |
#486 | /sitemap_index_3.xml | 219 |
#487 | /gold.php | 219 |
#488 | /api/v2/marketplace/sellers/615/products/queue | 219 |
#489 | /sitemap_index_7.xml | 218 |
#490 | /sitemap_index_2.xml | 218 |
#491 | /NewFile.php | 217 |
#492 | /en/assets/images/logos/HTB.JPG | 217 |
#493 | /gg.php | 217 |
#494 | /admin/kcfinder/upload.php | 217 |
#495 | /wsman | 216 |
#496 | /api/v2/marketplace/sellers/631/products/batch | 216 |
#497 | /sitemap_index_6.xml | 216 |
#498 | /application.properties | 216 |
#499 | /ff2.php | 216 |
#500 | /site/wp-includes/wlwmanifest.xml | 214 |
Data was last updated on: Sep 17, 2025
We love logs. In this section we will share some of the data we are parsing from our logs and honeypots we have live.
Logging for fun and a good night of sleep.
Latest log-based threat analysis added.
Do you have an idea for a research that is not here? See something wrong? Contact us at support@noc.org
14 days free trial. No credit card required.