flocmaterials.shop: a new server that handed out PowerShell scripts for VIP Keylogger, and what to do if one ran

flocmaterials.shop is a web address registered on 28 September 2026 that URLhaus lists six times on 5 and 6 October 2026 for PowerShell scripts called secured_stub.ps1, all tagged VIPKeylogger and two also MassLogger, password stealers for Windows. The files are now offline.

A script like this is not something you catch by reading a page; it is a step that an email attachment or another script already running on a PC fetches. If you only saw the name, nothing is proven. If something on your PC asked for it, treat your passwords as stolen and follow the plan below.

Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

If a script or attachment that downloads PowerShell files from flocmaterials.shop keeps coming back after uninstalling, a scan can find what reinstalls it.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove flocmaterials.shop (VIP Keylogger and MassLogger PowerShell scripts) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Table of six URLhaus entries for flocmaterials.shop, each a PowerShell file called secured_stub.ps1, all offline, tagged VIPKeylogger and two also MassLogger
The six URLhaus entries for flocmaterials.shop that we read on 6 October 2026. Our only check of the site was a plain request from our server, which got a placeholder page, so this table of reports is the main evidence.

Flocmaterials.shop (VIP Keylogger and MassLogger PowerShell scripts): summary

TypeA malware server: URLhaus tags its PowerShell scripts VIPKeylogger, and two of them MassLogger (Windows password stealers)
RiskHigh if a script on your PC fetched its files: passwords, cookies, keystrokes and clipboard may be taken. Low if you only saw the name
SymptomsOften none. A UserInitMprLogonScript value you did not set, aspnet_compiler.exe running for no reason and unexpected sign in alerts are the signs in the reports
How to get rid of itChange passwords from another device, run Microsoft Defender Offline, remove the startup entries, and reset Windows if you are not sure
Our check (6 October 2026)One plain request from our server to the front page: HTTP 200, a Cloudflare placeholder page. That clears nothing; the danger rating comes from URLhaus
Running since / first seenDomain registered 28 September 2026; first scripts reported 5 October 2026; all six offline by 6 October 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformWindows. Nothing we read says Mac or phones are affected
Detection namesNo Microsoft name is known for these exact files, because we did not open them. Microsoft uses Trojan:MSIL/Masslogger!MTB for MassLogger and Trojan:MSIL/SnakeKeylogger!MTB for the related Snake Keylogger
NameFlocmaterials.shop
Domain registered28 September 2026
Evidence6 write-ups by security sites; details still limited
First seen5 October 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked6 October 2026

Facts checked on 6 October 2026 against the URLhaus data for flocmaterials.shop held in our database, RDAP, one plain request from our server to the front page (no browser, no clicks), and published reports by Splunk, Forcepoint, Mandiant, Microsoft and the FTC. We did not download the scripts and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.

What flocmaterials.shop is, and what we know about it

flocmaterials.shop is not a program on your PC. It is a web address that the abuse.ch project URLhaus lists six times, between 5 and 6 October 2026, for PowerShell scripts tagged VIPKeylogger, and two of them also MassLogger. Both names belong to Windows keyloggers that steal passwords. We found no public write-up of this one address, so what follows is what URLhaus shows, what our server saw when it asked for the front page, and what security vendors have published about the malware families named in the tags.

  1. 1

    What URLhaus lists

    Six file addresses on flocmaterials.shop, each in its own folder with a short odd name (nzzee6, ceofrnd29, myceo30, ceofrnd1, mrceofrnnd, nzeceo) and each called secured_stub.ps1. A .ps1 file is a PowerShell script, a text file of commands that Windows can run. Five were added on 5 October 2026 within two minutes of each other, and one more on 6 October 2026. All six carry the threat label malware_download and the reporter abuse_ch.

  2. 2

    What the tags mean

    VIPKeylogger is on all six, MassLogger on two. powershell and ps1 say what kind of file it is. ascii says the file is plain text. opendir means the folder could be listed in a browser, an open directory, which is how such files are often found by researchers.

  3. 3

    Where the files are now

    In the data we read on 6 October 2026, all six entries are marked offline. That means the files no longer answered when URLhaus checked them. It does not mean a PC that already ran one is clean, and the same operator can put new files up at any time.

  4. 4

    What this means for you

    If you only saw the name in a list, a log or a news item, nothing on your PC is proven. If a script, an email attachment or a program on your Windows PC asked for one of these addresses, treat the PC as possibly running a keylogger and follow the plan below.

Kind of threat
A server that handed out PowerShell scripts tagged VIPKeylogger, two also tagged MassLogger; both are Windows password stealers
Where the files were
hxxps://flocmaterials[.]shop/<folder>/secured_stub.ps1, six folders, all offline when we read the data
Domain registered
28 September 2026 through Spaceship, Inc., status client transfer prohibited (RDAP, read 6 October 2026)
First and last report
5 October 2026 09:13 UTC and 6 October 2026 08:05 UTC
Front page today
HTTP 200 from a Cloudflare server with the page title Application placeholder (a plain request from our server on 6 October 2026)
Platform
Windows. PowerShell scripts and both malware families are described only for Windows

What flocmaterials.shop (VIP Keylogger and MassLogger PowerShell scripts) does on an infected PC

What we checked on 6 October 2026, and what we could not

Our check was one plain request from our server to the front page of flocmaterials.shop, with no browser, no clicks and no attempt to fetch the reported scripts. It answered, but an answer like that clears nothing: a malware server can show an empty page at its front door and keep its files in folders nobody is meant to guess.

Our check, 6 October 2026

  • The front page answeredOur server got HTTP status 200 from a server that names itself cloudflare, and the page title was Application placeholder. No redirect was sent. A placeholder like this is what a freshly set up hosting account shows before a real site is added.
  • Why that is not a clean resultThe reported files sat in separate folders, not on the front page. A quiet front page is common for this kind of server and is not a sign of safety.
  • Notification requestsThe answer did not mention the browser notification feature. That is expected: this is not a pop-up site.
  • URLhaus listingSix PowerShell scripts named secured_stub.ps1, all tagged VIPKeylogger and two also MassLogger, reported on 5 and 6 October 2026.
  • The files themselvesAll six are marked offline in the data we read. We did not download any script, so we cannot tell you what each one contains or where it pointed next.

Dangerous: treat it as a malware server Our request proves nothing either way. The danger rating comes from the six URLhaus reports and their tags. Do not open folders on this address, and do not run any .ps1 file that came from it.

What happened to flocmaterials.shop, from registration to our check

The domain is only days old, and the reports came within a week of the registration. The dates come from RDAP and from the URLhaus data we hold; the times are UTC.

  1. 28 September 2026

    The domain is registered

    RDAP shows flocmaterials.shop registered at 21:25 UTC on 28 September 2026 through Spaceship, Inc. The name reads like a shop for building or craft materials. We found no shop of that name behind it.

  2. 5 October 2026, 09:13

    The first script is reported

    URLhaus adds hxxps://flocmaterials[.]shop/nzeceo/secured_stub.ps1, tagged VIPKeylogger and MassLogger, reporter abuse_ch.

  3. 5 October 2026, 09:14

    Four more scripts in one minute

    Four further folders (ceofrnd29, myceo30, ceofrnd1, mrceofrnnd) are added, each with the same file name secured_stub.ps1, all tagged VIPKeylogger.

  4. 6 October 2026, 08:05

    A sixth script

    One more, in the folder nzzee6, tagged VIPKeylogger and MassLogger. Like the others, it is marked offline in the data we read.

  5. 6 October 2026

    Our check

    Our server asked for the front page once and got a Cloudflare placeholder page. We read the RDAP record the same day.

Table of six URLhaus entries for flocmaterials.shop, each a file called secured_stub.ps1 in a different folder, all offline, tagged VIPKeylogger and two also MassLogger
The six URLhaus entries for flocmaterials.shop that we read on 6 October 2026. Our check of the front page only showed a placeholder, so this table of reports is the main evidence.

What the pattern suggests, and what it does not: a new domain, a name that looks harmless, many folders with the same file inside and reports within days are what disposable delivery servers often look like. That is our reading of the dates and names, not something any report on this domain says. The folder names with ceo in them may hint at lures aimed at company staff, but we found nothing that confirms it.

How a PowerShell stub fits into a keylogger attack

A .ps1 file does not infect a PC by being listed on a web page. It does harm when something already running on the PC downloads it and starts PowerShell with it. We did not see a victim's PC; this is how Splunk and Forcepoint describe the chain for VIP Keylogger.

Five steps: a fake payment or shipping email, a script or RTF attachment runs, a PowerShell stub is fetched, the loader is pulled from a PNG picture, and the keylogger sends stolen data out
The chain vendors describe for VIP Keylogger. The files on flocmaterials.shop match step 3 by their type and name; the first steps on a real victim's PC are not something we saw.
  1. 1

    An email with a reason to open it

    Splunk (13 May 2026) says the lures pose as bank payment notifications, procurement orders and logistics updates. Forcepoint (13 December 2024) describes emails with RTF files that look like Office documents.

  2. 2

    A first script runs

    Splunk describes VBS, JavaScript and batch files padded with junk code so scanners miss them, which decode a PowerShell stager. Forcepoint describes RTF files that abuse CVE-2017-11882, an old flaw in Microsoft Office, to download the next file.

  3. 3

    PowerShell fetches the next part

    A file called secured_stub.ps1 fits this step by name and type. A stub is a small piece of code whose job is to fetch or unpack the real program. We did not read these files, so we cannot say which exact role they had.

  4. 4

    The loader hides in a picture

    Splunk describes the PowerShell stage downloading a PNG picture with the loader hidden inside it, and storing data in an environment variable called INTERNAL_DB_CACHE.

  5. 5

    The keylogger runs inside a real Windows program

    Splunk says the final payload is injected into aspnet_compiler.exe, a genuine .NET tool, so it looks like normal activity. It comes back after each sign in through the UserInitMprLogonScript registry value.

Because each step only fetches the next, the server that is offline today may already have done its job on PCs that asked for it earlier. That is why an offline status is not good news for someone who ran the first file.

What VIP Keylogger and MassLogger are

Both are password stealers for Windows written in .NET and sold or passed among criminals. The tags say which family the reporter believed the scripts lead to; the sources describe the families in general, not these six files.

QuestionWhat the sources saySource
What is VIP Keylogger?An information stealer spread by phishing; it shares a lot with Snake Keylogger, also known as 404 KeyloggerForcepoint X-Labs, 13 December 2024
How is VIP Keylogger delivered today?VBS, JS or BAT loaders, PowerShell stagers, a PNG with the loader hidden in it, and injection into aspnet_compiler.exe; Splunk reviewed more than 200 loader samplesSplunk, 13 May 2026
Where does VIP Keylogger send data?Telegram bots and command servers, including dynamic DuckDNS addressesSplunk; Forcepoint
What is MassLogger?A .NET credential stealer that rewrites its own code while it runs to frustrate analysisMandiant (Google Cloud), 6 August 2020
Where does MassLogger send data?By email over SMTP, by FTP or to a web panel, as set in its configurationMandiant
How does Microsoft name them?Trojan:MSIL/Masslogger!MTB, alert level severe; Trojan:MSIL/SnakeKeylogger!MTB for the related Snake familyMicrosoft Security Intelligence

What flocmaterials.shop (VIP Keylogger and MassLogger PowerShell scripts) can steal or download

What these keyloggers can take from a Windows PC

A keylogger records what you do and sends it out quietly. Each item below is named by at least one of the sources for VIP Keylogger or MassLogger; no single build is known to do all of them.

Reported as stolen

  • Every key you type
  • Saved browser passwords
  • Browser cookies and autofill
  • Outlook and Thunderbird logins
  • Discord tokens
  • Telegram data
  • Wi-Fi passwords
  • Screenshots
  • Clipboard, including crypto wallet addresses
  • FTP logins such as FileZilla
  • VPN client data
  • PC name, country and IP address
DataDetailSource
LoginsPasswords, cookies and autofill from browsers; Outlook credentialsSplunk; Forcepoint; Mandiant
TypingKeystroke logsSplunk; Mandiant
Screen and clipboardScreenshots and clipboard text, with attention to crypto wallet addressesSplunk; Forcepoint
AppsDiscord tokens; Telegram, Pidgin, FileZilla, NordVPN, Thunderbird and QQ Browser dataSplunk; Mandiant
NetworkWi-Fi passwords and the public IP and location of the PCSplunk; Mandiant

What this can cost you

Reading about the site or seeing its name costs nothing. The risks below apply to a Windows PC where a script fetched one of these files and the keylogger then ran.

  • High

    Email and every account it resets

    A stolen email password, or a stolen session cookie, lets someone reset other accounts. The FTC stresses that email deserves special attention for this reason.

  • High

    Money

    Bank logins typed on the PC and crypto addresses changed on the clipboard can mean direct loss. Check balances and recent payments from another device.

  • High

    Work accounts

    The lures named by Splunk are business emails about payments and orders, so a work PC with company mail, VPN or file sharing logins is a likely target. Tell your IT team at once.

  • Medium

    Your contacts

    A stolen mailbox can send the same kind of lure to people who trust you. The FTC advises warning friends and family if an account was taken.

  • Medium

    More malware

    A loader chain can fetch anything. We cannot say that these scripts only lead to a keylogger.

What you may notice, and what you may not

Keyloggers are built to be quiet, and most victims notice nothing until an account is misused. The signs below come from the sources or follow from them; none is certain.

SignWhat the reports show
A PowerShell window that flashed and closedThe chain runs PowerShell from a script; a short black window after opening an attachment is a warning sign
aspnet_compiler.exe running when you are not building softwareSplunk says the payload is injected into this genuine .NET tool
A logon script value you did not setSplunk names the UserInitMprLogonScript value under HKEY_CURRENT_USER\Environment as the way it starts at each sign in
Large or strange values in your environment variablesSplunk mentions INTERNAL_DB_CACHE and oversized entries under HKEY_CURRENT_USER\Environment
A copied crypto address that changes when pastedClipboard theft of wallet addresses is named by Splunk
Sign in alerts or password reset emails you did not ask forThe stolen data is used after the fact; this is often the first thing people see
Slow PC, crashes, changed filesMicrosoft lists these as possible symptoms on its SnakeKeylogger entry; they are common and not specific

How to check the PC for flocmaterials.shop (VIP Keylogger and MassLogger PowerShell scripts)

How a person ends up with one of these scripts

Nobody visits a folder like ceofrnd29 on flocmaterials.shop on purpose. The request comes from a script or a document, so the real question is how that first file got onto the PC. We cannot say for this server; the routes below are the ones vendors found for these families.

  1. 1

    A business email with an attachment

    A payment advice, a purchase order or a shipping update, with a compressed file, a script or an RTF document attached. Splunk and Forcepoint both describe this as the start.

  2. 2

    An old Office flaw

    Forcepoint describes RTF files that use CVE-2017-11882. A PC with Office updates missing is the one at risk.

  3. 3

    Macros and scripts

    MassLogger has been spread through Office documents with malicious macros and through phishing attachments, according to the vendor write-ups we read.

  4. 4

    A link you were told to follow

    A link to a downloadable file that turns out to be a .vbs, .js or .bat file. Showing file endings in File Explorer makes this easier to spot.

Check your PC before you delete anything

Start with the question that matters: did something on this PC contact flocmaterials.shop, or did you open an unexpected attachment, script or document in early October 2026? If you saw the name in a firewall or DNS log, the device that asked is the one to check. If the answer is yes or you are not sure, do the checks below. None of them deletes anything.

While you check, do not type passwords on this PC. Anything you type may be recorded.

  1. 1

    Disconnect first

    Turn off Wi-Fi or unplug the network cable. A keylogger needs the connection to send what it collected.

  2. 2

    Find which device asked

    If you came here from a log, a router page or an alert, note the device and the time. Only that device is in question.

  3. 3

    Look at the logon script value

    Press Start, type regedit and open it. Go to HKEY_CURRENT_USER\Environment. A value named UserInitMprLogonScript is rarely used on home PCs; if it exists and you did not set it, note what it runs. Also note any very long values or one named INTERNAL_DB_CACHE. Do not delete yet.

  4. 4

    Look at startup programs

    Open Settings > Apps > Startup, then the Startup folder (press Win+R, type shell:startup). Forcepoint says VIP Keylogger copies itself to startup folders.

  5. 5

    Look at scheduled tasks

    Open Task Scheduler and look in Task Scheduler Library for tasks you do not know that run PowerShell, wscript or a file from a user folder.

  6. 6

    Look at running programs

    Open Task Manager and look for aspnet_compiler.exe or PowerShell running with no reason. Their presence is not proof; they are real Windows parts.

  7. 7

    Open Protection history

    In Windows Security > Virus & threat protection > Protection history, look for detections with Masslogger, SnakeKeylogger or VIPKeylogger in the name, or for anything blocked around the time you opened the attachment.

  8. 8

    Check your accounts from another device

    Look at sign in activity of your email, bank, work and crypto accounts. This is quicker than any file check.

How to remove flocmaterials.shop (VIP Keylogger and MassLogger PowerShell scripts)

How to remove flocmaterials.shop

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Programs like flocmaterials.shop add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.

    On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.

    Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.

    Right-click an entry and choose Open file location to see where it runs from: programs in %AppData% or %Temp% deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.

    Press Windows + R, type %LocalAppData% and press Enter, then do the same for %AppData% and %ProgramData%, and look for folders named after flocmaterials.shop, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.

    If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    A scan finds the parts of flocmaterials.shop that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Flocmaterials.shop can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.

    Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.

    Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

If you use a Mac, an iPhone or an Android phone

The files are PowerShell scripts and every source we read describes Windows malware. We found nothing that says flocmaterials.shop affects anything else.

Your deviceWhat we knowWhat to do
MacNo source describes VIP Keylogger or MassLogger on a Mac, and the chain relies on Windows scriptsNothing to remove for this threat. Do not follow the Windows steps on a Mac
iPhone or iPadNo source mentions themNothing to remove. If you typed passwords on the Windows PC, change them from here
AndroidNo source mentions themNothing to remove for this threat. A phone is a good clean device for changing passwords

After removal: passwords, accounts and prevention

After a clean PC: protect what was taken

The PC is one half. The other half is everything you typed or saved on it while the keylogger ran. The order matters: another device first, then the PC.

Five steps in order: disconnect the PC, change passwords from another device, run Microsoft Defender Offline, remove what starts with Windows, reset Windows if unsure
The order of actions if a script like this ran on a PC. The steps follow Microsoft and FTC pages; we did not test them on an infected PC.
  1. 1

    Change passwords from a clean device

    Start with email, because it resets everything else, then bank, work, shops, Discord and crypto. Saved browser passwords should all be treated as known.

  2. 2

    Sign out other sessions and turn on two step sign in

    The FTC says to sign out of all devices, turn on two factor authentication and check that recovery details are yours. This makes stolen cookies useless.

  3. 3

    Check mail rules and sent items

    The FTC advises looking for forwarding rules and messages you did not send. Attackers who read business mail often add a quiet forwarding rule.

  4. 4

    Run Microsoft Defender Offline

    In Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and Scan now. Microsoft says it takes about 15 minutes and restarts the PC, and that BitLocker should be suspended first.

  5. 5

    Remove what starts with Windows

    Delete the UserInitMprLogonScript value, unknown Startup entries and unknown scheduled tasks that you noted earlier, then restart and check that they did not come back.

  6. 6

    Reset Windows if you are not sure

    Microsoft's reset is in Settings > System > Recovery > Reset PC. Remove everything with Cloud download gives a fresh copy of Windows. Back up documents first, not programs.

  7. 7

    Tell the people who need to know

    Your IT team for a work PC, your bank if money moved, and your contacts if your mailbox sent anything.

If you own flocmaterials.shop or the hosting account

The domain was registered on 28 September 2026 and showed only a placeholder page when we checked. If it is yours and you did not put these files there, the account or the server was misused.

  1. 1

    Look for the folders

    Search the web root for the six folder names and for any file called secured_stub.ps1, and for other scripts you did not upload.

  2. 2

    Turn off directory listing

    The opendir tag means folder contents could be listed. Disable listing in the server or hosting settings.

  3. 3

    Change hosting, registrar and Cloudflare passwords

    Use two step sign in on each, and check for users or API keys you did not create.

  4. 4

    Ask for delisting only when it is clean

    URLhaus records come from reports; once the files are gone and the account is secured, contact abuse.ch with the details.

Keep a PC out of this kind of chain

The PowerShell stub is a middle step. Every vendor write-up we read starts earlier, with a file a person opened.

Do

  • Treat an unexpected payment, order or shipping email with an attachment as suspect, even from a known company name.
  • Keep Windows and Office updated; Forcepoint's chain relies on a flaw fixed years ago.
  • Show file endings in File Explorer so a .vbs, .js or .bat file posing as a document is visible.
  • Use a password manager and two step sign in, so one stolen password is not enough.
  • Keep a backup of documents on a disk that you unplug.

Don't

  • Do not open RTF, script or compressed attachments you did not expect.
  • Do not click to enable content or macros in a document from email.
  • Do not type passwords on a PC you suspect.
  • Do not rely on a server being offline to mean you are safe.
  • Do not rely on a quiet scan alone to say that the PC is clean.

Questions about flocmaterials.shop (VIP Keylogger and MassLogger PowerShell scripts)

What is flocmaterials.shop?

It is a web address that URLhaus, the malware tracking project run by abuse.ch, lists for six PowerShell scripts, all called secured_stub.ps1, tagged VIPKeylogger and two also MassLogger. They were reported on 5 and 6 October 2026.

It is not a program on your PC, and we found no real shop behind the name. We did not download the scripts, so their exact content is not confirmed by us.

Is flocmaterials.shop still dangerous if the files are offline?

For new visitors, less so today, because all six files were marked offline in the data we read. For a PC that already ran one of them, offline changes nothing: the keylogger may already be installed.

The same operator can also upload new files at any time. New folders on the same address, or the same file name on a new domain, would not show up in this list until someone reports them.

Can visiting the site infect my PC?

We have no report that the front page does anything; it showed a placeholder page to our server. The danger is a .ps1 file being run by PowerShell, which needs a script, a document or a person to start it.

A browser that opens a .ps1 link only downloads it as text. Still, there is no reason to visit the address, and our single request is not a full test of what the server can do.

What does VIP Keylogger steal?

Splunk and Forcepoint list browser passwords, cookies and autofill, Outlook logins, Discord tokens, Wi-Fi passwords, screenshots, clipboard contents and keystrokes, sent out through Telegram bots or command servers.

Splunk adds that it looks up the public location of the PC, and Forcepoint names the PC name, country and email settings among the data taken. Anything you typed or saved on the PC while it ran should be treated as known to the attacker.

What is MassLogger?

A .NET password stealer described by Mandiant in 2020. It takes credentials from browsers, email and chat programs, records keys and the clipboard, and sends the data by email, FTP or to a web panel.

Microsoft detects it as Trojan:MSIL/Masslogger!MTB. Microsoft rates that detection as severe. Two of the six scripts on flocmaterials.shop carry the MassLogger tag next to VIPKeylogger, which shows the reporter's view, not a test of ours.

How do I know if my PC is infected?

Often you will not see anything. Look for a UserInitMprLogonScript value under HKEY_CURRENT_USER\Environment, unknown startup entries or tasks, aspnet_compiler.exe running for no reason, detections in Protection history, and unexpected sign in alerts on your accounts.

None of these signs is proof on its own, and their absence does not clear the PC. The first question is simpler: did you open an attachment or run a script around 5 or 6 October 2026?

Is a Microsoft Defender scan enough?

A scan helps, and Microsoft Defender Offline is better for hidden malware, but a clean result is one data point.

If you ran a suspicious attachment and cannot be sure, reset Windows with Remove everything after changing your passwords from another device. Microsoft says the offline scan takes about 15 minutes, restarts the PC, and shows its results in Protection history.

Do I need to change my passwords?

Yes, if a script from this address ran on your PC. Change them from another device, starting with email, and sign out other sessions. Changing them on the infected PC lets the keylogger record the new ones.

Then turn on two step sign in, check recovery addresses and mail forwarding rules, and look at recent payments. The FTC lists these same steps for a hacked account.

Does this affect Mac, iPhone or Android?

No source we read says so. The files are PowerShell scripts and both malware families are described only for Windows. If you use a Mac or a phone, there is nothing to remove for this threat.

What you can do from those devices is change the passwords that you typed on a Windows PC that may have run one of these scripts, and check your account activity.

Will Fortect remove flocmaterials.shop?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For flocmaterials.shop, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove porterneuman.mx: PowerShell and JavaScript files tied to the AveMaria remote access trojan, and what to do

porterneuman.mx is a web address where URLhaus found five script files in a WordPress plugin folder on 30 September 2026: four PowerShell stubs and one JavaScript file. One stub is tagged AveMariaRAT, a remote access...TrojansHigh riskUgnius Kiguolis ·

Remove Memz virus

Memz virus is the custom-made trojan that overwrites Windows boot sequence with Nyan Cat meme animation Memz virus is the trojan originally created by Leurak as viewer-made malware forTrojansHigh riskLucia Danes ·

Remove qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran

qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger, two keyloggers that steal passwords...TrojansHigh riskUgnius Kiguolis ·

Remove www.beinke-aufzuege.de: a hacked website hosting FormBook PowerShell stubs, and what to do if a script fetched them

www.beinke-aufzuege.de is the address of a German website that URLhaus lists for four PowerShell files tagged Formbook, a password stealer for Windows, hidden in random folders inside the site's own Joomla media...TrojansHigh riskUgnius Kiguolis ·

Questions and experiences: flocmaterials.shop (VIP Keylogger and MassLogger PowerShell scripts)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year