spinstall0.aspx is a malicious ASPX web shell observed in active exploitation of on-premises Microsoft SharePoint Server vulnerabilities including the ToolShell chain (CVE-2025-49704 and CVE-2025-49706) and related bypass variants CVE-2025-53770 and CVE-2025-53771. In observed attacks, actors sent crafted POST requests to SharePoint, including to /_layouts/15/ToolPane.aspx, and wrote the web shell to the server, with reporting placing it at C:\PROGRA~1\COMMON~1\MICROS~1\WEBSER~1\16\TEMPLATE\LAYOUTS\spinstall0.aspx. Variant filenames included spinstall.aspx, spinstall1.aspx, and spinstall2.aspx. The web shell is used to retrieve SharePoint ASP.NET MachineKey material, specifically ValidationKey, DecryptionKey, and server compatibility mode settings, and return the results via a GET request. This key material can then be used to forge signed __VIEWSTATE payloads, enabling persistence and arbitrary command execution even after patching unless keys are rotated. Reporting also describes related ASPX shells used for cmd.exe execution and file upload. Microsoft and other vendors associated this activity with exploitation against internet-facing on-premises SharePoint servers across government, telecommunications, software, manufacturing, critical infrastructure, professional services, defense, NGOs, higher education, media, financial, and health sectors. Microsoft observed Chinese threat actors Linen Typhoon and Violet Typhoon exploiting the SharePoint flaws, and tracked Storm-2603 using the exploits to deploy web shells including spinstall0.aspx, steal MachineKeys, establish persistence, dump credentials with Mimikatz, move laterally with PsExec, Impacket, and WMI, disable Defender protections via registry changes, manipulate IIS components to load suspicious .NET assemblies, and distribute Warlock ransomware via Group Policy Objects. Reported attacker infrastructure included source IPs 104.238.159[.]149, 107.191.58[.]76, and 96.9.125[.]147.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In observed attacks, threat actors send a crafted POST request to the SharePoint server, uploading a malicious script named spinstall0.aspx... The spinstall0.aspx script contains commands to retrieve MachineKey data and return the results to the user through a GET request, enabling the theft of the key material by threat actors.
In observed attacks, threat actors send a crafted POST request to the SharePoint server, uploading a malicious script named spinstall0.aspx... The spinstall0.aspx script contains commands to retrieve MachineKey data and return the results to the user through a GET request, enabling the theft of the key material by threat actors.
In observed attacks, threat actors send a crafted POST request to the SharePoint server, uploading a malicious script named spinstall0.aspx... The spinstall0.aspx script contains commands to retrieve MachineKey data and return the results to the user through a GET request, enabling the theft of the key material by threat actors.
In observed attacks, threat actors send a crafted POST request to the SharePoint server, uploading a malicious script named spinstall0.aspx... The spinstall0.aspx script contains commands to retrieve MachineKey data and return the results to the user through a GET request, enabling the theft of the key material by threat actors.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In observed attacks, threat actors send a crafted POST request to the SharePoint server, uploading a malicious script named spinstall0.aspx... The spinstall0.aspx script contains commands to retrieve MachineKey data and return the results to the user through a GET request, enabling the theft of the key material by threat actors.
In observed attacks, threat actors send a crafted POST request to the SharePoint server, uploading a malicious script named spinstall0.aspx... The spinstall0.aspx script contains commands to retrieve MachineKey data and return the results to the user through a GET request, enabling the theft of the key material by threat actors.
In observed attacks, threat actors send a crafted POST request to the SharePoint server, uploading a malicious script named spinstall0.aspx... The spinstall0.aspx script contains commands to retrieve MachineKey data and return the results to the user through a GET request, enabling the theft of the key material by threat actors.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
After gaining code execution, the attacker typically drops an ASP.NET webshell into a SharePoint web application directory... Webshells observed in the wild use password-protected access, XOR-encrypted command strings, file upload capabilities, and cookie-based authentication to evade detection.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
spinstall0.aspx is a custom ASP.NET web shell deployed on vulnerable SharePoint servers. Unlike traditional web shells, it is primarily used for reconnaissance and persistence, extracting cryptographic secrets (ValidationKey, DecryptionKey, cryptographic mode) from the host. These secrets allow attackers to forge authentication or session tokens, maintain persistent access, and potentially move laterally across load-balanced SharePoint environments.
SharePoint web shell used after exploitation to retrieve ASP.NET MachineKey material, enable command execution, and maintain access on compromised servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.