Web logs 404 analysis - past 72 hours
Dec 5, 2025
Automatically updated daily

Checking for 404 errors in your logs can reveal more than just broken links, it can also expose files and URLs that attackers are actively scanning for. To track this behavior, we set up hundreds of honeypots and analyzed live web traffic data, giving us insight into which files and URLs are being targeted across the internet.


This table bellow list the top URLs being scanned in the past 72 hours. Some of them may show what attacker are actively looking for and new vulnerabilities in the wild.


Rank Scanned URL Counter
#1 /wp-login.php35,777
#2 /autodiscover/autodiscover.xml18,758
#3 /.well-known/traffic-advice10,215
#4 /api/v2/auth6,698
#5 /saiga.php5,048
#6 /.env4,922
#7 /4043,766
#8 /api/v2/products/55183,517
#9 /wp-content/video3,158
#10 /xmlrpc.php2,952
#11 /shop2,870
#12 /admin.php2,393
#13 /api/v2/products/22472,365
#14 /index.php2,081
#15 /sitemap.xml2,051
#16 /api/v2/marketplace/sellers/376/products/status-batch1,991
#17 /api/v2/marketplace/sellers/376/products/stock-batch1,989
#18 /api/v2/marketplace/sellers/376/products/price-batch1,987
#19 /[object%20Object]1,850
#20 /api/v2/products/16593706901,800
#21 /api/v2/products/16593695921,799
#22 /api/v2/products/16593705401,794
#23 /api/v2/products/16593714621,794
#24 /api/v2/products/16593703151,790
#25 /api/v2/products/16593698631,788
#26 /api/v2/products/16593709401,787
#27 /api/v2/products/16593720221,785
#28 /api/v2/products/16593711941,784
#29 /api/v2/products/16593712171,784
#30 /api/v2/products/16593710291,782
#31 /api/v2/products/16593718841,781
#32 /api/v2/products/16593690381,781
#33 /api/v2/products/16593701431,780
#34 /api/v2/products/16593720421,778
#35 /api/v2/products/16593693181,778
#36 /api/v2/products/16593719501,776
#37 /api/v2/products/16593693661,776
#38 /api/v2/products/16593694851,774
#39 /api/v2/products/16593714891,774
#40 /api/v2/products/16593706491,774
#41 /api/v2/products/16593699411,766
#42 /api/v2/products/16593717301,762
#43 /api/v2/products/16593705391,762
#44 /api/v2/products/16593697651,761
#45 /api/v2/products/16593689751,749
#46 /.git/config1,677
#47 /upload/banner1,638
#48 /cdn-cgi/rum1,592
#49 /about.php1,580
#50 /api/v2/products/16593706611,566
#51 /info.php1,547
#52 /chosen.php1,538
#53 /wp-cron.php1,507
#54 /content.php1,496
#55 /api/.env1,486
#56 /api/v2/app/intermittent-fasting1,484
#57 /files1,411
#58 /files.php1,371
#59 /backend/.env1,323
#60 /export.php1,322
#61 /file_manager1,291
#62 /.well-known/passkey-endpoints1,289
#63 /file_manager.php1,238
#64 /file_upload1,235
#65 /admin/.env1,214
#66 /filter1,156
#67 /footer.php1,148
#68 /abcd.php1,123
#69 /fileupload1,118
#70 /api/sessions1,117
#71 /wp-json/oembed/1.0/embed1,102
#72 /functions1,102
#73 /forgot.php1,085
#74 /forgot1,083
#75 /header1,078
#76 /file.php1,074
#77 /functions.php1,071
#78 /header.php1,063
#79 /web_api/auth1,052
#80 /ioxi-o.php1,043
#81 /backup1,040
#82 /aa.php1,038
#83 /null1,035
#84 /wp-json/commerce/paypal/payments/payment-token997
#85 /tytyd.php994
#86 /wp-json/commerce/paypal/payments/start-trial979
#87 /wp-json/commerce/paypal/payments/order974
#88 /g/collect974
#89 /.env.example966
#90 /classwithtostring.php964
#91 /alfa.php955
#92 /moon.php949
#93 /contrato/wap/crons/enviar-email.php936
#94 /wp-json/commerce/paypal/payments/confirm931
#95 /app_dev.php/_profiler/phpinfo907
#96 /wp-admin888
#97 /1.php887
#98 /asasx.php876
#99 /api/v2/customers/login875
#100 /buy.php863
#101 /wp-good.php862
#102 /admin859
#103 /AutoDiscover/autodiscover.xml852
#104 /cong.php829
#105 /play/aula/conteudo/buscar/44285674829
#106 /xmrlpc.php821
#107 /bolt.php809
#108 /wp-includes/wlwmanifest.xml806
#109 /autoload_classmap.php797
#110 /default.php775
#111 /akcc.php770
#112 /wp-json/commerce/paypal/payments/cancel758
#113 /flower.php753
#114 /nc4.php738
#115 /new.php735
#116 /pagamento/mercadopago/ipn.php712
#117 /api708
#118 /goods.php705
#119 /function/function.php699
#120 /dropdown.php690
#121 /build.php690
#122 /demo/equipe/api/v2/auth689
#123 /login688
#124 /api/v1/677e09724f0e2df9b6c000b75b5da10d/conectala/freight682
#125 /play/aula/conteudo/buscar/23157962679
#126 /wordpress675
#127 /web/wp-includes/wlwmanifest.xml673
#128 /wordpress/wp-includes/wlwmanifest.xml671
#129 /file2.php670
#130 /wp/wp-includes/wlwmanifest.xml662
#131 /adminfuns.php654
#132 /makeasmtp.php653
#133 /api/v2/batch/1146649
#134 /wp648
#135 /api/v2/batch/1145644
#136 /2019/wp-includes/wlwmanifest.xml641
#137 /comment.php637
#138 /shop/wp-includes/wlwmanifest.xml635
#139 /api/v2/brands/4718631
#140 /feed629
#141 /old629
#142 /blog/wp-includes/wlwmanifest.xml628
#143 /assets/images/accesson.php625
#144 /-/-/-/-/-/-/-/-/-/-610
#145 /atomlib.php608
#146 /graphql607
#147 /api/graphql606
#148 /home604
#149 /admin/config.php603
#150 /website/wp-includes/wlwmanifest.xml587
#151 /new580
#152 /news/wp-includes/wlwmanifest.xml579
#153 /aaa.php574
#154 /filemanager.php568
#155 /api/v2/app/sleep-monitoring/setting564
#156 /elp.php563
#157 /style.php560
#158 /wp-admin/index.php557
#159 /administrator556
#160 /api/gql553
#161 /bless.php541
#162 /simular540
#163 /sitemap_index.xml537
#164 /bin535
#165 /ALFA_DATA/admin.php534
#166 /graphql/api533
#167 /test.php531
#168 /export529
#169 /admin/admin.php528
#170 /images/images/about.php526
#171 /comment-subscriptions526
#172 /mari.php523
#173 /xleet.php522
#174 /edit.php521
#175 /wso.php515
#176 /js509
#177 /test508
#178 /akc.php507
#179 /wp-content/plugins/hellopress/wp_filemanager.php502
#180 /about500
#181 /wp-content/wp-conflg.php493
#182 /api/v2/products/531485
#183 /rest/V1/store/storeViews482
#184 /item.php480
#185 /css.php476
#186 /ahax.php474
#187 /2018/wp-includes/wlwmanifest.xml474
#188 /ds.php473
#189 /wp-content/plugins/fix/up.php471
#190 /api/v2/marketplace/sellers/655/products/queue471
#191 /api/v2/marketplace/sellers/425/products/queue469
#192 /api/v2/marketplace/sellers/615/products/queue469
#193 /api/v2/marketplace/sellers/537/products/queue469
#194 /en/autodiscover/autodiscover.xml468
#195 /core.php468
#196 /api/v2/batch/1190467
#197 /api/v2/batch/1183467
#198 /api/v2/batch/1176466
#199 /api/v2/batch/1186465
#200 /api/v2/batch/1188464
#201 /api/v2/batch/1185464
#202 /api/v2/batch/1182464
#203 /api/v2/batch/1181464
#204 /api/v2/batch/1178464
#205 /api/v2/batch/1187464
#206 /api/v2/batch/1189463
#207 /api/v2/batch/1184463
#208 /api/v2/batch/1179463
#209 /api/v2/batch/1173463
#210 /api/v2/batch/1175463
#211 /api/v2/batch/1192462
#212 /api/v2/batch/1177462
#213 /api/v2/batch/1171462
#214 /api/v2/batch/1174462
#215 /api/v2/batch/1194461
#216 /api/v2/batch/1191461
#217 /api/v2/batch/1168461
#218 /api/v2/batch/1169461
#219 /api/v2/batch/1170461
#220 /api/v2/batch/1172460
#221 /api/v2/batch/1193459
#222 /wp-content/plugins/yanierin/akcc.php456
#223 /images455
#224 /+CSCOL+/a1.jar454
#225 /+CSCOL+/Java.jar453
#226 /debug/default/view451
#227 /umbro/masculino449
#228 /blog448
#229 /postnews.php448
#230 /lowpr.php447
#231 /api/v2/batch/1166445
#232 /module/ngmercadolivre/notificacao444
#233 /api/v2/batch/1165443
#234 /.__info.php442
#235 /phpinfo441
#236 /api/v2/batch/1142441
#237 /.env.local440
#238 /play/aula/conteudo/buscar/75016992438
#239 /new4.php435
#240 /_profiler/phpinfo431
#241 /api/v2/batch/1126431
#242 /api/v2/batch/1198430
#243 /api/v2/batch/1148430
#244 /v2/_catalog430
#245 /api/v2/batch/1121429
#246 /api/v2/batch/1117428
#247 /api/v2/batch/1149428
#248 /api/v2/batch/1124428
#249 /api/v2/batch/1120428
#250 /api/v2/batch/1214427
#251 /api/v2/batch/1127427
#252 /api/v2/batch/1118427
#253 /api/v2/batch/1128426
#254 /api/v2/batch/1115426
#255 /404.php424
#256 /api/v2/batch/1125424
#257 /api/v2/batch/1129423
#258 /api/v2/batch/1111423
#259 /api/v2/batch/1116422
#260 /api/v2/batch/1119421
#261 /api/v2/batch/1114420
#262 /cgi-bin420
#263 /manager.php418
#264 /api/v2/batch/1113418
#265 /api/v2/batch/1110417
#266 /wp-content/index.php416
#267 /install.php414
#268 /telescope/requests414
#269 /server-status411
#270 /api/v2/products/386407
#271 /en/AutoDiscover/autodiscover.xml401
#272 /404testpage4525d2fdc399
#273 /api/v2/marketplace/sellers/376/products/queue397
#274 /filemanager/dialog.php397
#275 /api/v2/marketplace/sellers/376/products/batch396
#276 /test1.php396
#277 /simple.php391
#278 /wp-content/plugins/cartflows/assets/fonts389
#279 /inputs.php389
#280 /ava.php385
#281 /api/v2/products/248381
#282 /app/webroot/filemanager.php379
#283 /zuk.php378
#284 /umbro376
#285 /sts.php376
#286 /api/v2/batch/1219375
#287 /wp-admin/includes375
#288 /api/v2/batch/1218374
#289 /image.php374
#290 /fox.php374
#291 /mail.php372
#292 /wp-content/plugins/wpsearch/login.php367
#293 /app/.env364
#294 /wp-content/postnews.php364
#295 /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application362
#296 /umbro/feminino361
#297 /papelariafofa361
#298 /.aws/credentials357
#299 /pow.php356
#300 /.well-known/acme-challenge/about.php355
#301 /sitemap-index.xml354
#302 /fss.php354
#303 /App/__healthcheck350
#304 /simular-credito-trabalhador348
#305 /hplfuns.php346
#306 /wp.php345
#307 /form.php345
#308 /wp-admin/postnews.php343
#309 /login.action341
#310 /swagger/index.html339
#311 /file4.php338
#312 /swagger-ui.html336
#313 /webjars/swagger-ui/index.html335
#314 /shell.php334
#315 /fm.php332
#316 /lock360.php329
#317 /swagger/swagger-ui.html327
#318 /_all_dbs322
#319 /server322
#320 /wp-content/upgrade/index.php315
#321 /laravel/.env313
#322 /cache.php312
#323 /uploads311
#324 /actuator/env308
#325 /wp-admin/css/colors/blue/index.php308
#326 /wp1/wp-includes/wlwmanifest.xml306
#327 /sso/ifood/play/player/6305193305
#328 /@vite/env304
#329 /.env.development301
#330 /app/impulse/products300
#331 /wp-json/commerce/paypal/payments/cards299
#332 /minha-conta-atk299
#333 /config/.env293
#334 /4ec82611292
#335 /HNAP1291
#336 /wso112233.php289
#337 /wp-admin/css286
#338 /appWP/lab/wp-admin/css/colors/blue/blue.php286
#339 /as.php285
#340 /v2/api-docs285
#341 /customers.php283
#342 /wp-content/plugins/pwnd/pwnd.php281
#343 /submissions281
#344 /databases.yml281
#345 /new/.env278
#346 /themes.php277
#347 /cp277
#348 /wp-admin/network/plugin-privacy.php277
#349 /go.php276
#350 /wp-admin/about.php274
#351 /portal/.env274
#352 /dead.letter274
#353 /customers274
#354 /play/aula/conteudo/buscar/55403970274
#355 /pb273
#356 /loja/cartService.php273
#357 /radio.php270
#358 /callback.php270
#359 /loja/login_layout.php269
#360 /wordpress/wp-admin/setup-config.php269
#361 /s/1313e2236313e20373e2538313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties268
#362 /wp-admin/includes/class-action.php268
#363 /gmo.php266
#364 /customer/account/create266
#365 /play/aula/conteudo/buscar/20757514266
#366 /fr262
#367 /minha-conta/pedidoapi/v2/front/checkout/cart261
#368 /config.php261
#369 /.git/credentials261
#370 /wp-content/plugins/elementor/assets/lib/font-awesome/webfonts260
#371 /lv.php260
#372 /v3/api-docs260
#373 /images/index.php259
#374 /web_api/products255
#375 /www/.env253
#376 /app/config/parameters.yml253
#377 /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php251
#378 /file5.php251
#379 /wp-includes/style-engine250
#380 /pinfo.php250
#381 /test/wp-includes/wlwmanifest.xml247
#382 /sitemap.php246
#383 /loja/busca.php246
#384 /autoload_classmap/function.php243
#385 /php.php243
#386 /RDWeb/Pages241
#387 /wp-editor.php239
#388 /index/function.php236
#389 /api/v2/marketplace/sellers/425/orders/queue236
#390 /api/v2/marketplace/sellers/537/orders/queue236
#391 /apps/.env236
#392 /api/v2/marketplace/sellers/615/orders/queue235
#393 /api/v2/marketplace/sellers/655/orders/queue235
#394 /api/v2/batch/162620234
#395 /api/v2/batch/162619234
#396 /api/v2/batch/162570234
#397 /api/v2/batch/162569234
#398 /api/v2/batch/162562234
#399 /api/v2/batch/162546234
#400 /api/v2/batch/162545234
#401 /api/v2/batch/162530234
#402 /api/v2/batch/162529234
#403 /api/v2/batch/162525234
#404 /api/v2/batch/162523234
#405 /api/v2/batch/162452234
#406 /api/v2/batch/162451234
#407 /api/v2/batch/162432234
#408 /api/v2/batch/162431234
#409 /api/v2/batch/162210234
#410 /api/v2/batch/162209234
#411 /api/v2/batch/162208234
#412 /api/v2/batch/162131234
#413 /api/v2/batch/162130234
#414 /api/v2/batch/162129234
#415 /api/v2/batch/162114234
#416 /api/v2/batch/162113234
#417 /api/v2/batch/162009234
#418 /api/v2/batch/162007234
#419 /api/v2/batch/162002234
#420 /api/v2/batch/162001234
#421 /api/v2/batch/161999234
#422 /api/v2/batch/161998234
#423 /api/v2/batch/161997234
#424 /api/v2/batch/161990234
#425 /api/v2/batch/161989234
#426 /api/v2/batch/161988234
#427 /api/v2/batch/161981234
#428 /api/v2/batch/161980234
#429 /api/v2/batch/161979234
#430 /api/v2/batch/161971234
#431 /api/v2/batch/161970234
#432 /api/v2/batch/161969234
#433 /api/v2/batch/161877234
#434 /api/v2/batch/161876234
#435 /api/v2/batch/161875234
#436 /api/v2/batch/161865234
#437 /api/v2/batch/161863234
#438 /api/v2/batch/161859234
#439 /api/v2/batch/161857234
#440 /api/v2/batch/161762234
#441 /api/v2/batch/161761234
#442 /api/v2/batch/161563234
#443 /api/v2/batch/161562234
#444 /api/v2/batch/161561234
#445 /api/v2/batch/1264234
#446 /api/v2/batch/1263234
#447 /api/v2/batch/1261234
#448 /api/v2/batch/1260234
#449 /api/v2/batch/1259234
#450 /api/v2/batch/1257234
#451 /api/v2/batch/1256234
#452 /api/v2/batch/1252234
#453 /api/v2/batch/161550234
#454 /api/v2/batch/1251234
#455 /api/v2/batch/161549234
#456 /api/v2/batch/1250234
#457 /api/v2/batch/161397234
#458 /api/v2/batch/1249234
#459 /api/v2/batch/1248234
#460 /api/v2/batch/160672234
#461 /api/v2/batch/160671234
#462 /api/v2/batch/160590234
#463 /api/v2/batch/1243234
#464 /api/v2/batch/160367234
#465 /api/v2/batch/1241234
#466 /api/v2/batch/160365234
#467 /api/v2/batch/1240234
#468 /api/v2/batch/1239234
#469 /api/v2/batch/160246234
#470 /api/v2/batch/1238234
#471 /api/v2/batch/1237234
#472 /api/v2/batch/160232234
#473 /api/v2/batch/160231234
#474 /api/v2/batch/160230234
#475 /api/v2/batch/160226234
#476 /api/v2/batch/160225234
#477 /api/v2/batch/1236234
#478 /api/v2/batch/160224234
#479 /api/v2/batch/1233234
#480 /api/v2/batch/1232234
#481 /api/v2/batch/159979234
#482 /api/v2/batch/1231234
#483 /api/v2/batch/1230234
#484 /api/v2/batch/159978234
#485 /api/v2/batch/159918234
#486 /api/v2/batch/1228234
#487 /api/v2/batch/1227234
#488 /api/v2/batch/1226234
#489 /api/v2/batch/1222234
#490 /api/v2/batch/159853234
#491 /api/v2/batch/159718234
#492 /api/v2/batch/501255234
#493 /api/v2/batch/430861234
#494 /api/v2/batch/461100234
#495 /api/v2/batch/467777234
#496 /api/v2/batch/310229234
#497 /api/v2/batch/3315234
#498 /api/v2/batch/162571233
#499 /api/v2/batch/162561233
#500 /api/v2/batch/162560233


Data was last updated on: Dec 5, 2025



Logging Research

We love logs. In this section we will share some of the data we are parsing from our logs and honeypots we have live.

Trunc Logging

Logging for fun and a good night of sleep.

  • Real time search
  • Google simple
  • Cheap
  • Just works
  • PCI compliance
Trunc Research

Latest log-based threat analysis added.

Contact us!

Do you have an idea for a research that is not here? See something wrong? Contact us at support@noc.org

Tired of price gouging
  • Clear pricing
  • No need to guess
  • Real people
  • Real logging

Simple, Affordable, Log Management and Analysis.

14 days free trial. No credit card required.