logo

Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)

ID: ed3d9f69-23ba-502a-b90f-feafc49fbff6

STIX ID: report--ed3d9f69-23ba-502a-b90f-feafc49fbff6

Feed Name: SANS ISC Diary

Threat Score
25/100

Date Published: 2026-08-10

Date Updated: 2026-08-10

...
...

Observed automated scanner activity (User-Agent: HelloScan/1.0) probing web servers for Solana JSON-RPC endpoints by sending POST requests such as `{"jsonrpc":"2.0","id":1,"method":"getHealth"}` to paths like `/solana`, `/jsonrpc`, `/rpc`, `/v1` and enumerating potential credential files (e.g., `/.env`, `/.env.bak`, `/.env.local`). Responses from Surfpool-like development backends return `{"jsonrpc":"2.0","result":"ok","id":1}`; the traffic appears to be reconnaissance/fingerprinting on port 80 (likely assuming a proxy to backend port 8899) rather than active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.