logo

[Guest Diary] Hunting for SharePoint In-Memory ToolShell Payloads, (Tue, Dec 2nd)

ID: 86b5c7a6-a8ba-5f31-b41b-c35c49805c7c

STIX ID: report--86b5c7a6-a8ba-5f31-b41b-c35c49805c7c

Feed Name: SANS ISC Diary

Threat Score
78/100

Date Published: 2025-12-01

Date Updated: 2026-04-19

...
...

This guest-hunting diary documents detection and analysis of the ToolShell SharePoint exploit chain (CVE-2025-53770/53771). It demonstrates using Zeek logs and PCAP analysis (DaemonLogger, mergecap, Wireshark) to identify malicious POST requests to ToolPane.aspx, extract and decode the CompressedDataTable payload, and reveal in-memory .NET DLLs (e.g., osvmhdfl.dll, jlaneafi.dll) and encoded PowerShell used for reconnaissance and exfiltration, plus scanner payloads and relevant IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.