GhostContainer backdoor loaded via Exchange VIEWSTATE tampering

Detects potential exploitation attempts against Microsoft Exchange Server, specifically targeting the ECP (Exchange Control Panel) through VIEWSTATE parameter tampering related to CVE-2020-0688, and correlates this with suspicious behavior in the w3wp.exe process, such as unauthorized module loading (e.g., clr.dll, system.web.dll) and abnormal child process creation which may indicate the deployment of in-memory backdoors like GhostContainer.