flocmaterials.shop: a new server that handed out PowerShell scripts for VIP Keylogger, and what to do if one ran
flocmaterials.shop is a web address registered on 28 September 2026 that URLhaus lists six times on 5 and 6 October 2026 for PowerShell scripts called secured_stub.ps1, all tagged VIPKeylogger and two also MassLogger, password stealers for Windows. The files are now offline.
A script like this is not something you catch by reading a page; it is a step that an email attachment or another script already running on a PC fetches. If you only saw the name, nothing is proven. If something on your PC asked for it, treat your passwords as stolen and follow the plan below.
Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
If a script or attachment that downloads PowerShell files from flocmaterials.shop keeps coming back after uninstalling, a scan can find what reinstalls it.
Do it yourself · free Remove flocmaterials.shop (VIP Keylogger and MassLogger PowerShell scripts) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Flocmaterials.shop (VIP Keylogger and MassLogger PowerShell scripts): summary
| Type | A malware server: URLhaus tags its PowerShell scripts VIPKeylogger, and two of them MassLogger (Windows password stealers) |
|---|---|
| Risk | High if a script on your PC fetched its files: passwords, cookies, keystrokes and clipboard may be taken. Low if you only saw the name |
| Symptoms | Often none. A UserInitMprLogonScript value you did not set, aspnet_compiler.exe running for no reason and unexpected sign in alerts are the signs in the reports |
| How to get rid of it | Change passwords from another device, run Microsoft Defender Offline, remove the startup entries, and reset Windows if you are not sure |
| Our check (6 October 2026) | One plain request from our server to the front page: HTTP 200, a Cloudflare placeholder page. That clears nothing; the danger rating comes from URLhaus |
| Running since / first seen | Domain registered 28 September 2026; first scripts reported 5 October 2026; all six offline by 6 October 2026 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Platform | Windows. Nothing we read says Mac or phones are affected |
|---|---|
| Detection names | No Microsoft name is known for these exact files, because we did not open them. Microsoft uses Trojan:MSIL/Masslogger!MTB for MassLogger and Trojan:MSIL/SnakeKeylogger!MTB for the related Snake Keylogger |
| Name | Flocmaterials.shop |
| Domain registered | 28 September 2026 |
| Evidence | 6 write-ups by security sites; details still limited |
| First seen | 5 October 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 6 October 2026 |
Facts checked on 6 October 2026 against the URLhaus data for flocmaterials.shop held in our database, RDAP, one plain request from our server to the front page (no browser, no clicks), and published reports by Splunk, Forcepoint, Mandiant, Microsoft and the FTC. We did not download the scripts and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.
What flocmaterials.shop is, and what we know about it
flocmaterials.shop is not a program on your PC. It is a web address that the abuse.ch project URLhaus lists six times, between 5 and 6 October 2026, for PowerShell scripts tagged VIPKeylogger, and two of them also MassLogger. Both names belong to Windows keyloggers that steal passwords. We found no public write-up of this one address, so what follows is what URLhaus shows, what our server saw when it asked for the front page, and what security vendors have published about the malware families named in the tags.
- 1
What URLhaus lists
Six file addresses on flocmaterials.shop, each in its own folder with a short odd name (nzzee6, ceofrnd29, myceo30, ceofrnd1, mrceofrnnd, nzeceo) and each called secured_stub.ps1. A .ps1 file is a PowerShell script, a text file of commands that Windows can run. Five were added on 5 October 2026 within two minutes of each other, and one more on 6 October 2026. All six carry the threat label malware_download and the reporter abuse_ch.
- 2
What the tags mean
VIPKeylogger is on all six, MassLogger on two. powershell and ps1 say what kind of file it is. ascii says the file is plain text. opendir means the folder could be listed in a browser, an open directory, which is how such files are often found by researchers.
- 3
Where the files are now
In the data we read on 6 October 2026, all six entries are marked offline. That means the files no longer answered when URLhaus checked them. It does not mean a PC that already ran one is clean, and the same operator can put new files up at any time.
- 4
What this means for you
If you only saw the name in a list, a log or a news item, nothing on your PC is proven. If a script, an email attachment or a program on your Windows PC asked for one of these addresses, treat the PC as possibly running a keylogger and follow the plan below.
- Kind of threat
- A server that handed out PowerShell scripts tagged VIPKeylogger, two also tagged MassLogger; both are Windows password stealers
- Where the files were
- hxxps://flocmaterials[.]shop/<folder>/secured_stub.ps1, six folders, all offline when we read the data
- Domain registered
- 28 September 2026 through Spaceship, Inc., status client transfer prohibited (RDAP, read 6 October 2026)
- First and last report
- 5 October 2026 09:13 UTC and 6 October 2026 08:05 UTC
- Front page today
- HTTP 200 from a Cloudflare server with the page title Application placeholder (a plain request from our server on 6 October 2026)
- Platform
- Windows. PowerShell scripts and both malware families are described only for Windows
What flocmaterials.shop (VIP Keylogger and MassLogger PowerShell scripts) does on an infected PC
What we checked on 6 October 2026, and what we could not
Our check was one plain request from our server to the front page of flocmaterials.shop, with no browser, no clicks and no attempt to fetch the reported scripts. It answered, but an answer like that clears nothing: a malware server can show an empty page at its front door and keep its files in folders nobody is meant to guess.
Our check, 6 October 2026
- The front page answeredOur server got HTTP status 200 from a server that names itself cloudflare, and the page title was Application placeholder. No redirect was sent. A placeholder like this is what a freshly set up hosting account shows before a real site is added.
- Why that is not a clean resultThe reported files sat in separate folders, not on the front page. A quiet front page is common for this kind of server and is not a sign of safety.
- Notification requestsThe answer did not mention the browser notification feature. That is expected: this is not a pop-up site.
- URLhaus listingSix PowerShell scripts named secured_stub.ps1, all tagged VIPKeylogger and two also MassLogger, reported on 5 and 6 October 2026.
- The files themselvesAll six are marked offline in the data we read. We did not download any script, so we cannot tell you what each one contains or where it pointed next.
Dangerous: treat it as a malware server Our request proves nothing either way. The danger rating comes from the six URLhaus reports and their tags. Do not open folders on this address, and do not run any .ps1 file that came from it.
What happened to flocmaterials.shop, from registration to our check
The domain is only days old, and the reports came within a week of the registration. The dates come from RDAP and from the URLhaus data we hold; the times are UTC.
28 September 2026
The domain is registered
RDAP shows flocmaterials.shop registered at 21:25 UTC on 28 September 2026 through Spaceship, Inc. The name reads like a shop for building or craft materials. We found no shop of that name behind it.
5 October 2026, 09:13
The first script is reported
URLhaus adds hxxps://flocmaterials[.]shop/nzeceo/secured_stub.ps1, tagged VIPKeylogger and MassLogger, reporter abuse_ch.
5 October 2026, 09:14
Four more scripts in one minute
Four further folders (ceofrnd29, myceo30, ceofrnd1, mrceofrnnd) are added, each with the same file name secured_stub.ps1, all tagged VIPKeylogger.
6 October 2026, 08:05
A sixth script
One more, in the folder nzzee6, tagged VIPKeylogger and MassLogger. Like the others, it is marked offline in the data we read.
6 October 2026
Our check
Our server asked for the front page once and got a Cloudflare placeholder page. We read the RDAP record the same day.

What the pattern suggests, and what it does not: a new domain, a name that looks harmless, many folders with the same file inside and reports within days are what disposable delivery servers often look like. That is our reading of the dates and names, not something any report on this domain says. The folder names with ceo in them may hint at lures aimed at company staff, but we found nothing that confirms it.
How a PowerShell stub fits into a keylogger attack
A .ps1 file does not infect a PC by being listed on a web page. It does harm when something already running on the PC downloads it and starts PowerShell with it. We did not see a victim's PC; this is how Splunk and Forcepoint describe the chain for VIP Keylogger.

- 1
An email with a reason to open it
Splunk (13 May 2026) says the lures pose as bank payment notifications, procurement orders and logistics updates. Forcepoint (13 December 2024) describes emails with RTF files that look like Office documents.
- 2
A first script runs
Splunk describes VBS, JavaScript and batch files padded with junk code so scanners miss them, which decode a PowerShell stager. Forcepoint describes RTF files that abuse CVE-2017-11882, an old flaw in Microsoft Office, to download the next file.
- 3
PowerShell fetches the next part
A file called secured_stub.ps1 fits this step by name and type. A stub is a small piece of code whose job is to fetch or unpack the real program. We did not read these files, so we cannot say which exact role they had.
- 4
The loader hides in a picture
Splunk describes the PowerShell stage downloading a PNG picture with the loader hidden inside it, and storing data in an environment variable called INTERNAL_DB_CACHE.
- 5
The keylogger runs inside a real Windows program
Splunk says the final payload is injected into aspnet_compiler.exe, a genuine .NET tool, so it looks like normal activity. It comes back after each sign in through the UserInitMprLogonScript registry value.
Because each step only fetches the next, the server that is offline today may already have done its job on PCs that asked for it earlier. That is why an offline status is not good news for someone who ran the first file.
What VIP Keylogger and MassLogger are
Both are password stealers for Windows written in .NET and sold or passed among criminals. The tags say which family the reporter believed the scripts lead to; the sources describe the families in general, not these six files.
| Question | What the sources say | Source |
|---|---|---|
| What is VIP Keylogger? | An information stealer spread by phishing; it shares a lot with Snake Keylogger, also known as 404 Keylogger | Forcepoint X-Labs, 13 December 2024 |
| How is VIP Keylogger delivered today? | VBS, JS or BAT loaders, PowerShell stagers, a PNG with the loader hidden in it, and injection into aspnet_compiler.exe; Splunk reviewed more than 200 loader samples | Splunk, 13 May 2026 |
| Where does VIP Keylogger send data? | Telegram bots and command servers, including dynamic DuckDNS addresses | Splunk; Forcepoint |
| What is MassLogger? | A .NET credential stealer that rewrites its own code while it runs to frustrate analysis | Mandiant (Google Cloud), 6 August 2020 |
| Where does MassLogger send data? | By email over SMTP, by FTP or to a web panel, as set in its configuration | Mandiant |
| How does Microsoft name them? | Trojan:MSIL/Masslogger!MTB, alert level severe; Trojan:MSIL/SnakeKeylogger!MTB for the related Snake family | Microsoft Security Intelligence |
What flocmaterials.shop (VIP Keylogger and MassLogger PowerShell scripts) can steal or download
What these keyloggers can take from a Windows PC
A keylogger records what you do and sends it out quietly. Each item below is named by at least one of the sources for VIP Keylogger or MassLogger; no single build is known to do all of them.
Reported as stolen
- Every key you type
- Saved browser passwords
- Browser cookies and autofill
- Outlook and Thunderbird logins
- Discord tokens
- Telegram data
- Wi-Fi passwords
- Screenshots
- Clipboard, including crypto wallet addresses
- FTP logins such as FileZilla
- VPN client data
- PC name, country and IP address
| Data | Detail | Source |
|---|---|---|
| Logins | Passwords, cookies and autofill from browsers; Outlook credentials | Splunk; Forcepoint; Mandiant |
| Typing | Keystroke logs | Splunk; Mandiant |
| Screen and clipboard | Screenshots and clipboard text, with attention to crypto wallet addresses | Splunk; Forcepoint |
| Apps | Discord tokens; Telegram, Pidgin, FileZilla, NordVPN, Thunderbird and QQ Browser data | Splunk; Mandiant |
| Network | Wi-Fi passwords and the public IP and location of the PC | Splunk; Mandiant |
What this can cost you
Reading about the site or seeing its name costs nothing. The risks below apply to a Windows PC where a script fetched one of these files and the keylogger then ran.
- High
Email and every account it resets
A stolen email password, or a stolen session cookie, lets someone reset other accounts. The FTC stresses that email deserves special attention for this reason.
- High
Money
Bank logins typed on the PC and crypto addresses changed on the clipboard can mean direct loss. Check balances and recent payments from another device.
- High
Work accounts
The lures named by Splunk are business emails about payments and orders, so a work PC with company mail, VPN or file sharing logins is a likely target. Tell your IT team at once.
- Medium
Your contacts
A stolen mailbox can send the same kind of lure to people who trust you. The FTC advises warning friends and family if an account was taken.
- Medium
More malware
A loader chain can fetch anything. We cannot say that these scripts only lead to a keylogger.
What you may notice, and what you may not
Keyloggers are built to be quiet, and most victims notice nothing until an account is misused. The signs below come from the sources or follow from them; none is certain.
| Sign | What the reports show |
|---|---|
| A PowerShell window that flashed and closed | The chain runs PowerShell from a script; a short black window after opening an attachment is a warning sign |
| aspnet_compiler.exe running when you are not building software | Splunk says the payload is injected into this genuine .NET tool |
| A logon script value you did not set | Splunk names the UserInitMprLogonScript value under HKEY_CURRENT_USER\Environment as the way it starts at each sign in |
| Large or strange values in your environment variables | Splunk mentions INTERNAL_DB_CACHE and oversized entries under HKEY_CURRENT_USER\Environment |
| A copied crypto address that changes when pasted | Clipboard theft of wallet addresses is named by Splunk |
| Sign in alerts or password reset emails you did not ask for | The stolen data is used after the fact; this is often the first thing people see |
| Slow PC, crashes, changed files | Microsoft lists these as possible symptoms on its SnakeKeylogger entry; they are common and not specific |
How to check the PC for flocmaterials.shop (VIP Keylogger and MassLogger PowerShell scripts)
How a person ends up with one of these scripts
Nobody visits a folder like ceofrnd29 on flocmaterials.shop on purpose. The request comes from a script or a document, so the real question is how that first file got onto the PC. We cannot say for this server; the routes below are the ones vendors found for these families.
- 1
A business email with an attachment
A payment advice, a purchase order or a shipping update, with a compressed file, a script or an RTF document attached. Splunk and Forcepoint both describe this as the start.
- 2
An old Office flaw
Forcepoint describes RTF files that use CVE-2017-11882. A PC with Office updates missing is the one at risk.
- 3
Macros and scripts
MassLogger has been spread through Office documents with malicious macros and through phishing attachments, according to the vendor write-ups we read.
- 4
A link you were told to follow
A link to a downloadable file that turns out to be a .vbs, .js or .bat file. Showing file endings in File Explorer makes this easier to spot.
Check your PC before you delete anything
Start with the question that matters: did something on this PC contact flocmaterials.shop, or did you open an unexpected attachment, script or document in early October 2026? If you saw the name in a firewall or DNS log, the device that asked is the one to check. If the answer is yes or you are not sure, do the checks below. None of them deletes anything.
While you check, do not type passwords on this PC. Anything you type may be recorded.
- 1
Disconnect first
Turn off Wi-Fi or unplug the network cable. A keylogger needs the connection to send what it collected.
- 2
Find which device asked
If you came here from a log, a router page or an alert, note the device and the time. Only that device is in question.
- 3
Look at the logon script value
Press Start, type regedit and open it. Go to HKEY_CURRENT_USER\Environment. A value named UserInitMprLogonScript is rarely used on home PCs; if it exists and you did not set it, note what it runs. Also note any very long values or one named INTERNAL_DB_CACHE. Do not delete yet.
- 4
Look at startup programs
Open Settings > Apps > Startup, then the Startup folder (press Win+R, type shell:startup). Forcepoint says VIP Keylogger copies itself to startup folders.
- 5
Look at scheduled tasks
Open Task Scheduler and look in Task Scheduler Library for tasks you do not know that run PowerShell, wscript or a file from a user folder.
- 6
Look at running programs
Open Task Manager and look for aspnet_compiler.exe or PowerShell running with no reason. Their presence is not proof; they are real Windows parts.
- 7
Open Protection history
In Windows Security > Virus & threat protection > Protection history, look for detections with Masslogger, SnakeKeylogger or VIPKeylogger in the name, or for anything blocked around the time you opened the attachment.
- 8
Check your accounts from another device
Look at sign in activity of your email, bank, work and crypto accounts. This is quicker than any file check.
How to remove flocmaterials.shop (VIP Keylogger and MassLogger PowerShell scripts)
How to remove flocmaterials.shop
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Programs like flocmaterials.shop add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.
On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.
Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 2: Remove it from startup
Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.
Right-click an entry and choose Open file location to see where it runs from: programs in
%AppData%or%Temp%deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.
Press Windows + R, type
%LocalAppData%and press Enter, then do the same for%AppData%and %ProgramData%, and look for folders named after flocmaterials.shop, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.
Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
A scan finds the parts of flocmaterials.shop that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Flocmaterials.shop can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.
Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.
Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
If you use a Mac, an iPhone or an Android phone
The files are PowerShell scripts and every source we read describes Windows malware. We found nothing that says flocmaterials.shop affects anything else.
| Your device | What we know | What to do |
|---|---|---|
| Mac | No source describes VIP Keylogger or MassLogger on a Mac, and the chain relies on Windows scripts | Nothing to remove for this threat. Do not follow the Windows steps on a Mac |
| iPhone or iPad | No source mentions them | Nothing to remove. If you typed passwords on the Windows PC, change them from here |
| Android | No source mentions them | Nothing to remove for this threat. A phone is a good clean device for changing passwords |
After removal: passwords, accounts and prevention
After a clean PC: protect what was taken
The PC is one half. The other half is everything you typed or saved on it while the keylogger ran. The order matters: another device first, then the PC.

- 1
Change passwords from a clean device
Start with email, because it resets everything else, then bank, work, shops, Discord and crypto. Saved browser passwords should all be treated as known.
- 2
Sign out other sessions and turn on two step sign in
The FTC says to sign out of all devices, turn on two factor authentication and check that recovery details are yours. This makes stolen cookies useless.
- 3
Check mail rules and sent items
The FTC advises looking for forwarding rules and messages you did not send. Attackers who read business mail often add a quiet forwarding rule.
- 4
Run Microsoft Defender Offline
In Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and Scan now. Microsoft says it takes about 15 minutes and restarts the PC, and that BitLocker should be suspended first.
- 5
Remove what starts with Windows
Delete the UserInitMprLogonScript value, unknown Startup entries and unknown scheduled tasks that you noted earlier, then restart and check that they did not come back.
- 6
Reset Windows if you are not sure
Microsoft's reset is in Settings > System > Recovery > Reset PC. Remove everything with Cloud download gives a fresh copy of Windows. Back up documents first, not programs.
- 7
Tell the people who need to know
Your IT team for a work PC, your bank if money moved, and your contacts if your mailbox sent anything.
If you own flocmaterials.shop or the hosting account
The domain was registered on 28 September 2026 and showed only a placeholder page when we checked. If it is yours and you did not put these files there, the account or the server was misused.
- 1
Look for the folders
Search the web root for the six folder names and for any file called secured_stub.ps1, and for other scripts you did not upload.
- 2
Turn off directory listing
The opendir tag means folder contents could be listed. Disable listing in the server or hosting settings.
- 3
Change hosting, registrar and Cloudflare passwords
Use two step sign in on each, and check for users or API keys you did not create.
- 4
Ask for delisting only when it is clean
URLhaus records come from reports; once the files are gone and the account is secured, contact abuse.ch with the details.
Keep a PC out of this kind of chain
The PowerShell stub is a middle step. Every vendor write-up we read starts earlier, with a file a person opened.
Do
- Treat an unexpected payment, order or shipping email with an attachment as suspect, even from a known company name.
- Keep Windows and Office updated; Forcepoint's chain relies on a flaw fixed years ago.
- Show file endings in File Explorer so a .vbs, .js or .bat file posing as a document is visible.
- Use a password manager and two step sign in, so one stolen password is not enough.
- Keep a backup of documents on a disk that you unplug.
Don't
- Do not open RTF, script or compressed attachments you did not expect.
- Do not click to enable content or macros in a document from email.
- Do not type passwords on a PC you suspect.
- Do not rely on a server being offline to mean you are safe.
- Do not rely on a quiet scan alone to say that the PC is clean.
Questions about flocmaterials.shop (VIP Keylogger and MassLogger PowerShell scripts)
What is flocmaterials.shop?
It is a web address that URLhaus, the malware tracking project run by abuse.ch, lists for six PowerShell scripts, all called secured_stub.ps1, tagged VIPKeylogger and two also MassLogger. They were reported on 5 and 6 October 2026.
It is not a program on your PC, and we found no real shop behind the name. We did not download the scripts, so their exact content is not confirmed by us.
Is flocmaterials.shop still dangerous if the files are offline?
For new visitors, less so today, because all six files were marked offline in the data we read. For a PC that already ran one of them, offline changes nothing: the keylogger may already be installed.
The same operator can also upload new files at any time. New folders on the same address, or the same file name on a new domain, would not show up in this list until someone reports them.
Can visiting the site infect my PC?
We have no report that the front page does anything; it showed a placeholder page to our server. The danger is a .ps1 file being run by PowerShell, which needs a script, a document or a person to start it.
A browser that opens a .ps1 link only downloads it as text. Still, there is no reason to visit the address, and our single request is not a full test of what the server can do.
What does VIP Keylogger steal?
Splunk and Forcepoint list browser passwords, cookies and autofill, Outlook logins, Discord tokens, Wi-Fi passwords, screenshots, clipboard contents and keystrokes, sent out through Telegram bots or command servers.
Splunk adds that it looks up the public location of the PC, and Forcepoint names the PC name, country and email settings among the data taken. Anything you typed or saved on the PC while it ran should be treated as known to the attacker.
What is MassLogger?
A .NET password stealer described by Mandiant in 2020. It takes credentials from browsers, email and chat programs, records keys and the clipboard, and sends the data by email, FTP or to a web panel.
Microsoft detects it as Trojan:MSIL/Masslogger!MTB. Microsoft rates that detection as severe. Two of the six scripts on flocmaterials.shop carry the MassLogger tag next to VIPKeylogger, which shows the reporter's view, not a test of ours.
How do I know if my PC is infected?
Often you will not see anything. Look for a UserInitMprLogonScript value under HKEY_CURRENT_USER\Environment, unknown startup entries or tasks, aspnet_compiler.exe running for no reason, detections in Protection history, and unexpected sign in alerts on your accounts.
None of these signs is proof on its own, and their absence does not clear the PC. The first question is simpler: did you open an attachment or run a script around 5 or 6 October 2026?
Is a Microsoft Defender scan enough?
A scan helps, and Microsoft Defender Offline is better for hidden malware, but a clean result is one data point.
If you ran a suspicious attachment and cannot be sure, reset Windows with Remove everything after changing your passwords from another device. Microsoft says the offline scan takes about 15 minutes, restarts the PC, and shows its results in Protection history.
Do I need to change my passwords?
Yes, if a script from this address ran on your PC. Change them from another device, starting with email, and sign out other sessions. Changing them on the infected PC lets the keylogger record the new ones.
Then turn on two step sign in, check recovery addresses and mail forwarding rules, and look at recent payments. The FTC lists these same steps for a hacked account.
Does this affect Mac, iPhone or Android?
No source we read says so. The files are PowerShell scripts and both malware families are described only for Windows. If you use a Mac or a phone, there is nothing to remove for this threat.
What you can do from those devices is change the passwords that you typed on a Windows PC that may have run one of these scripts, and check your account activity.
Will Fortect remove flocmaterials.shop?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For flocmaterials.shop, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Splunk Threat Research Team: Behind the Code, the layered defense evasion of VIP Keylogger (13 May 2026) (read October 6, 2026)
- Forcepoint X-Labs: VIPKeyLogger infostealer malware (13 December 2024) (read October 6, 2026)
- Mandiant (Google Cloud): Bypassing MassLogger anti-analysis, a man in the middle approach (6 August 2020) (read October 6, 2026)
- Microsoft Security Intelligence: Trojan:MSIL/Masslogger!MTB (updated 11 September 2020) (read October 6, 2026)
- Microsoft Security Intelligence: Trojan:MSIL/SnakeKeylogger!MTB (published 4 November 2021) (read October 6, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (updated 25 August 2026) (read October 6, 2026)
- Microsoft Support: Reset your PC (read October 6, 2026)
- FTC: How to recover your hacked email or social media account (read October 6, 2026)