Detects a persistent webshell named 'spinstall0.aspx' deployed on Microsoft SharePoint servers.
This file exposes sensitive cryptographic machineKey values from the SharePoint configuration,
indicating the presence of a ToolShell backdoor implant. This implant is linked to targeted
post-auth RCE campaigns exploiting CVE-2025-53770.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view