qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran
qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger, two keyloggers that steal passwords from Windows PCs.
Seeing the name in a log proves nothing by itself; if a script from an email may have run on your PC, change your passwords from another device, then scan with Microsoft Defender Offline or reset Windows.
Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
If a script or attachment that downloads .js or PowerShell files from qpwot.cfd keeps coming back after uninstalling, a scan can find what reinstalls it.
Do it yourself · free Remove qpwot.cfd (MassLogger and VIP Keylogger scripts) yourself 5 steps, about 15 minutes, no software needed.
Start the steps![Table of seven URLhaus entries for qpwot[.]cfd on 6 October 2026: three .js files and four secured_stub.ps1 files, tagged MassLogger and VIPKeylogger, three online](/pic/w1080q75/uploads/guides/qpwot-cfd-reports-2026-10.png.webp)
Qpwot.cfd (MassLogger and VIP Keylogger scripts): summary
| Type | A malware server: URLhaus lists JavaScript files and PowerShell stubs tagged MassLogger and VIPKeylogger, keyloggers and password stealers for Windows |
|---|---|
| Risk | High if one of its scripts ran on your PC: typed and saved passwords, cookies, cards and Wi-Fi passwords may be taken. Low if you only saw the name |
| Symptoms | Often none. A script opened from an email, aspnet_compiler.exe or dxdiag.exe running with no reason, and unknown values under HKEY_CURRENT_USER\Environment are the signs in the reports |
| How to get rid of it | Disconnect, change passwords from another device, run Microsoft Defender Offline, remove startup leftovers, and reset Windows if you are not sure |
| Our check (6 October 2026) | One plain request from our server: HTTP 200 through Cloudflare, a page titled Application placeholder. A quiet page clears nothing; the rating comes from URLhaus |
| Running since / first seen | Domain registered 1 October 2026; all seven files reported on 6 October 2026 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 10 more facts
| Platform | Windows. Nothing we read says Mac or phones are affected |
|---|---|
| Detection names | No Microsoft detection name is known for the files on this server, because we did not open them. For the families, Microsoft uses names such as Trojan:MSIL/MassLogger.MA!MTB and Trojan:MSIL/SnakeKeylogger!MSR |
| Name | Qpwot.cfd |
| Domain registered | 1 October 2026 |
| Evidence | 7 write-ups by security sites; details still limited |
| First seen | 6 October 2026 |
| Microsoft Defender name | no Microsoft detection name is known |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 6 October 2026 |
Facts checked on 6 October 2026 against the URLhaus data for qpwot.cfd held in our database (the abuse.ch host page itself showed a verification screen to our tool), RDAP, one plain request from our server, and published reports by Splunk, Seqrite, ANY.RUN, Infoblox, Cisco Talos via Security Affairs, Microsoft and the FTC.
We did not download the files and infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.
What qpwot.cfd is, and what we know about it
qpwot.cfd is not a program on your PC. It is a web address that URLhaus, the malware tracking project of abuse.ch, lists seven times on 6 October 2026 for script files: three JavaScript files and four PowerShell files named secured_stub.ps1. The PowerShell files are tagged MassLogger and VIPKeylogger, two Windows programs that record what you type and steal saved passwords. We found no public write-up of this one address, so this guide says what URLhaus shows, what our own request returned, and what vendors have published about the two families.
- 1
What URLhaus lists
Seven file addresses on qpwot.cfd, all over https, all added by the reporter abuse_ch between 07:03 and 07:14 UTC on 6 October 2026, and all with the threat label malware_download. Three end in .js and sit in folders called plug, plug2 and wealt/wealt1. Four are called secured_stub.ps1 and sit in folders called mrprince, wealt, pprriinnnce and ppprincee6. When we read the data, three were marked online and four offline.
- 2
What the tags mean
js and ps1 are the file types: JavaScript, which Windows can run with its built in script host, and PowerShell. opendir means the folder could be listed by anyone who asked the server, which is how the files were found together. ascii means the file is plain text. MassLogger and VIPKeylogger are names of the malware the PowerShell stubs are linked to; three stubs carry MassLogger, two carry VIPKeylogger, and one carries both.
- 3
What we could not confirm
We did not download any of the files, so we cannot say what each one does, which build of which keylogger it leads to, or where stolen data would be sent. URLhaus tags are the reporter's labels, not our proof. We also do not know how a victim's PC is told to fetch these files; that first step is not visible from the server side.
- 4
What this means for you
If you only saw the name in a firewall log, a DNS block list or a browser warning, that alone does not mean your PC is infected. The risk is for a Windows PC where a script was opened and went on to fetch a file from this address. Nobody is meant to visit these files in a browser.
- Kind of threat
- A server that hands out JavaScript and PowerShell files tagged MassLogger and VIPKeylogger, keyloggers and password stealers for Windows
- Example paths
- hxxps://qpwot[.]cfd/pprriinnnce/secured_stub.ps1 and hxxps://qpwot[.]cfd/plug/ (a .js file)
- Reports
- 7 in URLhaus, all on 6 October 2026; 3 online, 4 offline when we read them
- Registered
- 1 October 2026 at 01:35 UTC through Spaceship, Inc., five days before the first report
- Front page
- A plain request on 6 October 2026 got HTTP 200 through Cloudflare with the title Application placeholder
- Platform
- Windows. Every source we read describes Windows scripts and Windows programs
What qpwot.cfd (MassLogger and VIP Keylogger scripts) does on an infected PC
What we checked on 6 October 2026, and what we could not
We sent one plain request to https://qpwot.cfd/ from our server on 6 October 2026. It was not a browser, it ran no scripts and clicked nothing. The server answered with HTTP status 200, through Cloudflare, with a page titled Application placeholder. That clears nothing: it only tells us the front door of the server is open.
Our check of qpwot.cfd, 6 October 2026
- The front page answeredHTTP 200, server header cloudflare, no redirect, page title Application placeholder. A generic placeholder page is common on servers whose real use is somewhere else on the same address, here the script folders.
- Why that is not a clean resultA plain request is one look from one place. Servers that hand out malware often show a blank or harmless page to anyone who does not ask for the exact file path, and they can treat visitors differently by country, time or software.
- Notification requestThe page we received did not mention the browser notification feature. That was one request without a browser, so it proves nothing for later visits.
- URLhaus listingSeven malware_download entries on 6 October 2026: three .js files and four secured_stub.ps1 files tagged MassLogger, VIPKeylogger or both. Three still online when we read the data.
- The files themselvesWe did not request the script paths and did not open any file. We cannot tell you what is inside them.
Dangerous: treat it as a malware server Our request was one quiet look at a placeholder page, and a quiet look clears nothing. The danger rating comes from the seven URLhaus reports and their tags. Do not open files from this address and do not run anything that asks for it.
What happened to qpwot.cfd, from registration to our check
Everything happened within one week. The dates come from RDAP and from the URLhaus data we hold; times are UTC.
1 October 2026
The domain is registered
RDAP shows qpwot.cfd registered at 01:35 UTC through Spaceship, Inc., with the transfer locks that registries set by default. The name is five random looking letters under .cfd, a cheap generic ending. We draw no conclusion about the owner from that alone.
6 October 2026, 07:03 to 07:05
The first three files are reported
abuse_ch adds a .js file in plug2, a secured_stub.ps1 in ppprincee6 tagged MassLogger and VIPKeylogger, and a secured_stub.ps1 in pprriinnnce tagged MassLogger. The pprriinnnce file is still online when we read the data.
6 October 2026, 07:07 to 07:14
Four more files follow
A .js file in wealt/wealt1, a stub in wealt tagged VIPKeylogger, a .js file in plug and a stub in mrprince tagged MassLogger. The two .js files in wealt/wealt1 and plug stay online; the wealt and mrprince stubs are marked offline.
![Table of the seven URLhaus entries for qpwot[.]cfd on 6 October 2026 with times, paths, online or offline status and tags](/pic/w1080q75/uploads/guides/qpwot-cfd-reports-2026-10.png.webp)
The seven URLhaus entries for qpwot.cfd. The folder names change; the file name secured_stub.ps1 and the tags repeat. 6 October 2026
Our check
Our plain request to the front page gets HTTP 200 through Cloudflare and a page titled Application placeholder. We did not request any of the listed file paths.
What the pattern suggests, and what it does not: folders with similar names (prince spelled three ways, plug and plug2, wealt and wealt1) and the same stub file name in each look like one operator preparing several copies of the same chain, perhaps one per campaign or customer. That is our reading of the paths, not something any report says.
How a script on a server becomes a keylogger on a PC
A .js or .ps1 file on a server does nothing to you until something on your PC runs it. We did not see the chain for qpwot.cfd. The steps below are how Splunk (13 May 2026) and Seqrite describe VIP Keylogger chains, and how Cisco Talos and ANY.RUN describe MassLogger.

- 1
A business email with an attachment
Splunk says the lures pose as bank payment notices, purchase orders and shipping updates. Seqrite describes an email from a fake buyer with an attachment called Order Inquiry, a rich text file posing as a Word document. Cisco Talos describes MassLogger arriving in RAR archives that hide a compiled help file.
- 2
A script is opened
In Splunk's case the first file is a VBS, JavaScript or batch script. Opening it is enough: Windows runs .js and .vbs files with its own script host. The .js files listed on qpwot.cfd fit this step, but we did not open them.
- 3
A PowerShell stage is fetched
Splunk found the script decoding a PowerShell stager and storing it in a user environment variable named INTERNAL_DB_CACHE so that little is written to disk. Seqrite found a second script that starts PowerShell. The secured_stub.ps1 files on qpwot.cfd are named like such a stage.
- 4
The keylogger is decoded in memory
Both Splunk and Seqrite describe PNG or other picture files that carry encoded data. Seqrite shows the PowerShell code reading text between the markers BASE64_START and BASE64_END, reversing it, decoding it and loading it straight into memory without saving a program file.
- 5
It hides inside a real Windows program
Splunk names aspnet_compiler.exe as the program the keylogger is injected into; Seqrite names dxdiag.exe. In Task Manager the stealer then runs under a trusted name. Splunk says the chain makes itself start again at logon through the UserInitMprLogonScript registry value.
MassLogger and VIP Keylogger: what each one is
The tags name two families. Both are .NET programs for Windows sold to many different criminals, so the same name can show up in unrelated campaigns.
| MassLogger | VIP Keylogger | |
|---|---|---|
| First seen | April 2020, according to ANY.RUN and Infoblox | Documented by Seqrite and in detail by Splunk on 13 May 2026 |
| What it is | A .NET credential stealer and keylogger, sold as a service, according to ANY.RUN | A .NET keylogger and stealer delivered in several stages, per Seqrite and Splunk |
| What it takes | Keystrokes, clipboard, screenshots and logins from browsers, Outlook, Thunderbird, Discord, NordVPN, FileZilla and Telegram (Infoblox, Cisco Talos) | Saved passwords, cookies, history and card details from more than 40 browsers, keystrokes, screenshots, clipboard and Wi-Fi passwords (Splunk) |
| How data leaves | SMTP email, FTP or HTTP (Cisco Talos); ANY.RUN adds Telegram bots in recent samples | A Telegram bot and dedicated servers (Splunk) |
| Typical entry | Phishing emails with archives, help files or Office documents | Phishing emails with RTF files or VBS, JavaScript or batch scripts |
| Starts again after restart | ANY.RUN says many builds have no persistence; others add a Run key | UserInitMprLogonScript at logon (Splunk); a startup task or Run key option (Seqrite) |
Why both names on one file: a tag reflects what the reporter or an automatic rule recognised. Analysis sites often label related .NET stealers with more than one family name. We do not know which of the two the stubs on qpwot.cfd finally deliver, and it changes little for you: both record keys and take saved logins.
What qpwot.cfd (MassLogger and VIP Keylogger scripts) can steal or download
What these keyloggers can take from a Windows PC
The list below is what the families are reported to do. Each item is named by at least one source; one build may not do all of it.
Reported as taken
- Every key you type
- Passwords saved in browsers
- Browser cookies, which can keep you logged in elsewhere
- Saved card details
- Email logins from Outlook and Thunderbird
- Discord, Telegram and FileZilla logins
- NordVPN logins
- Wi-Fi passwords
- Clipboard contents
- Screenshots
- Crypto addresses swapped in the clipboard
| Data | Detail | Source |
|---|---|---|
| Browsers | Passwords, cookies, history, downloads and card details from 40 or more browsers | Splunk |
| Mail and chat | Outlook, Thunderbird, Discord, Pidgin, Telegram | Cisco Talos; Infoblox |
| Keys and screen | Keystrokes and screenshots; Splunk names a folder VIPRecovery under Documents for the screenshots | Splunk; ANY.RUN |
| Wi-Fi | Saved network passwords read with the netsh command | Splunk |
| Clipboard | Copied text, and crypto addresses replaced with the attacker's | Splunk; Infoblox |
What this can cost you
Seeing the name costs nothing. The risks below apply to a Windows PC where one of these scripts ran.
- High
Email and every account it resets
A stolen email password lets a stranger reset the passwords of almost everything else. Keyloggers also catch the new passwords you type on the same PC.
- High
Logged in sessions
Splunk lists browser cookies among the stolen data. A stolen session cookie can let someone into an account without the password, until you sign out everywhere.
- High
Money
Saved card details and banking logins are on the list, and the clipboard swap can send a crypto payment to the wrong wallet. Crypto sent cannot be pulled back.
- Medium
Work and business mail
The lures pose as orders and invoices, so work PCs are the usual target. A stolen work mailbox is often used for the next round of fake invoices to your customers.
- Medium
Other PCs and USB sticks
Infoblox says MassLogger can copy itself into files on connected USB drives. A stick used on the PC is worth scanning before you use it elsewhere.
- Low
Nothing, if you only saw the name
A name in a block list or a log is not an infection.
What you may notice, and what you may not
These stealers are built to be quiet. Most victims notice the stolen accounts before they notice anything on the PC.
| Sign | What the reports show |
|---|---|
| A .js, .vbs or .bat file you opened from an email | The usual first step in the Splunk and Seqrite chains |
| A PowerShell window that flashed and closed | PowerShell stages are part of both chains. A brief window is a common sign, though many run hidden |
| aspnet_compiler.exe or dxdiag.exe running with no reason | Splunk and Seqrite name these real Windows programs as hiding places. Their presence is not proof |
| A folder VIPRecovery in Documents | Splunk names it as the place screenshots are kept |
| A new value UserInitMprLogonScript or INTERNAL_DB_CACHE under HKEY_CURRENT_USER\Environment | Splunk names both |
| Account alerts | Sign ins from new places, password reset mail, messages you did not send |
| Nothing at all | Code that runs only in memory leaves little to see |
How to check the PC for qpwot.cfd (MassLogger and VIP Keylogger scripts)
Which name will your scanner show?
Microsoft's name for qpwot.cfd is no Microsoft detection name is known.
Defender sorts threats by category first, so the word before the colon tells you what kind of program was found, even if the family name means nothing to you.
Do not search for a removal tool by the detection name alone; fake "removal tools" use the same keywords. How the naming works is explained in our guide to antivirus detection names.
How a PC ends up asking for these files
Nobody types qpwot.cfd into a browser. The request comes from a script, so the real question is how that script reached the PC. We cannot say for this server; these are the routes the vendors found for the same families.
- 1
An email about an order, payment or delivery
Splunk names bank payment notices, purchase orders and logistics updates; Seqrite shows an Order Inquiry from a fake buyer; Infoblox shows an arrival notice that even links to a real shipping company's site to look genuine.
- 2
An attachment that is really a script
A file that looks like a document but ends in .js, .vbs, .bat, .wsf or .hta. Windows hides known file endings by default, so Invoice.pdf.js can look like Invoice.pdf.
- 3
An archive or a help file
Cisco Talos describes RAR archives split into parts and renamed to slip past filters, with a .chm help file inside that runs JavaScript.
- 4
A rich text file posing as Word
Seqrite's chain begins with an RTF file saved with a .doc ending that fetches the first script when it is opened.
Check your PC before you delete anything
Start with the question that matters: did you open an unexpected attachment, script or archive, or did a log show this PC contacting qpwot.cfd? If yes or not sure, do these checks. None of them deletes anything.
While you check, stop typing passwords on the PC. The FTC's first step for suspected malware is to stop logging in to accounts from the device.
- 1
Disconnect first
Turn off Wi-Fi or unplug the cable. A keylogger sends what it collects over the internet; without a connection it cannot.
- 2
Find which device asked
If the name came from a router, DNS filter or firewall log, note the device and the time. Only that device is in question.
- 3
Open Protection history
In Windows Security > Virus & threat protection > Protection history, look for anything blocked or quarantined around the time you opened the attachment. Microsoft names these families with labels such as Trojan:MSIL/MassLogger.MA!MTB and Trojan:MSIL/SnakeKeylogger!MSR; a name with MassLogger, SnakeKeylogger or VIPKeylogger in it is a strong sign.
- 4
Look for the files you opened
In Downloads and in your email program's temporary folder, look for .js, .vbs, .bat, .ps1, .rtf or .chm files from the same time. In File Explorer turn on View > Show > File name extensions so the real endings show.
- 5
Look at what starts with Windows
Open Task Scheduler and look in Task Scheduler Library for tasks you do not know that run a script, PowerShell or wscript. Then open Settings > Apps > Startup. Write down what you find; do not delete yet.
- 6
Look at the environment values Splunk names
Press Win + R, type regedit, and open HKEY_CURRENT_USER\Environment. A value called UserInitMprLogonScript or INTERNAL_DB_CACHE, or a very long value, is a strong sign. Do not edit the registry unless you are sure; note it and move to the scan.
- 7
Look in Task Manager
Open Task Manager and look for aspnet_compiler.exe, dxdiag.exe or powershell.exe running when you did not start them. They are real Windows programs, so this is a hint, not proof.
How to remove qpwot.cfd (MassLogger and VIP Keylogger scripts)
How to remove qpwot.cfd
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Programs like qpwot.cfd add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.
On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.
Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 2: Remove it from startup
Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.
Right-click an entry and choose Open file location to see where it runs from: programs in
%AppData%or%Temp%deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.
Press Windows + R, type
%LocalAppData%and press Enter, then do the same for%AppData%and %ProgramData%, and look for folders named after qpwot.cfd, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.
Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
A scan finds the parts of qpwot.cfd that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Qpwot.cfd can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.
Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.
Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
If you use a Mac, an iPhone or an Android phone
Every source we read describes Windows scripts and Windows programs. We found nothing that says the files on qpwot.cfd affect other systems.
| Your device | What we know | What to do |
|---|---|---|
| Mac | JavaScript files meant for the Windows script host and PowerShell stubs do not run this way on a Mac | Nothing to remove for this threat. Do not follow the Windows steps on a Mac |
| iPhone or iPad | No source mentions these families on iOS | Nothing to remove. If you typed passwords on a shared Windows PC, change them |
| Android | No source mentions them | Nothing to remove for this threat |
After removal: passwords, accounts and prevention
After a clean PC: protect what was taken
Cleaning the PC does not undo the theft. Anything typed or saved on it while the keylogger ran should be treated as known to someone else. Use another device for all of this.

- 1
Change passwords from a clean device
Start with email, then bank, work accounts, shops with saved cards, social media, Discord, Telegram, VPN and FTP accounts. Use new passwords, not small changes of old ones.
- 2
Sign out everywhere and turn on two step sign in
Because cookies may be stolen, use each service's option to sign out of all sessions. The FTC advises turning on two factor authentication where it is offered.
- 3
Call your bank about saved cards
Tell the bank the card details may have been stolen by malware and ask for a new card. Watch statements for small test charges.
- 4
Change the Wi-Fi password
Splunk lists Wi-Fi passwords among the stolen data. Change it in your router's settings and reconnect your devices.
- 5
Warn your contacts at work
If a work mailbox was on the PC, tell your IT team or your regular customers that fake invoices might come from your address.
- 6
Report it
In the US you can report identity theft at IdentityTheft.gov and get a recovery plan. Elsewhere, use your national police or cybercrime reporting service.
Keep a PC out of this kind of chain
The server is the middle of the chain. Every write-up we read starts with a file someone opened from an email.
Do
- Turn on File name extensions in File Explorer so a script posing as a document shows its real ending.
- Treat an unexpected order, invoice, payment or delivery attachment as an attack until the sender confirms it by phone.
- Keep Windows and Microsoft Defender updated.
- Use a password manager instead of saving passwords in the browser, and turn on two step sign in.
- Keep a backup of documents on a disk you unplug.
- At work, ask IT to block .js, .vbs and .hta attachments at the mail server.
Don't
- Do not open .js, .vbs, .bat, .wsf, .hta or .chm files that came by email.
- Do not open archives with odd endings such as .r00 from people you do not know.
- Do not change passwords on the PC you suspect.
- Do not trust a placeholder or blank page as a sign that a server is harmless.
- Do not take a quiet scan as proof that nothing ran.
Questions about qpwot.cfd (MassLogger and VIP Keylogger scripts)
What is qpwot.cfd?
It is a web address that URLhaus, the malware tracking project of abuse.ch, lists for seven script files reported on 6 October 2026: three JavaScript files and four PowerShell files named secured_stub.ps1. The PowerShell files are tagged MassLogger and VIPKeylogger, which are keyloggers and password stealers for Windows. The domain was registered on 1 October 2026 through Spaceship, Inc.
Its front page shows a placeholder titled Application placeholder through Cloudflare. It is not a program on your PC and not a site anyone is meant to visit. We did not download the files, so their exact content is not confirmed by us.
Is qpwot.cfd safe to open?
No. Treat it as a malware server. The seven URLhaus reports, all tagged malware_download, are the reason; our own plain request to the front page returned only a placeholder, and a quiet page clears nothing. Opening the front page in a browser is not how these files hurt people, because they need to be run as scripts on Windows.
Still, there is no reason to visit it, and a server that hands out malware can change what it shows at any time. Do not open any file that came from this address, and do not run a script or attachment that asks for it.
I saw qpwot.cfd in my firewall or DNS log. Am I infected?
Not by that alone. A blocked request means your filter did its job. But a request to this address usually comes from a script, not from a person, so find the device that made it and the time.
Then ask whether someone on that device opened an email attachment, archive or script shortly before. If yes, follow the checks in this guide:
- disconnect it
- look at Protection history
- Task Scheduler
- startup apps and the HKEY_CURRENT_USER\Environment values Splunk names
- then run Microsoft Defender Offline
If the request was blocked and nothing was opened, keep watching the device but there is no proof of infection.
What is MassLogger?
MassLogger is a keylogger and credential stealer for Windows written in .NET. ANY.RUN and Infoblox say it was first seen in April 2020, and ANY.RUN describes it as sold to criminals as a service. It records keystrokes and the clipboard, takes screenshots and steals logins from browsers, Outlook, Thunderbird, Discord, NordVPN, FileZilla and Telegram.
Cisco Talos found it sending stolen data by email, FTP or HTTP, and ANY.RUN lists Telegram bots in recent samples. It usually arrives in phishing emails with archives, help files or Office documents. Three of the PowerShell files on qpwot.cfd carry the MassLogger tag.
What is VIP Keylogger?
VIP Keylogger is another .NET keylogger and stealer for Windows. Splunk's research team described it in detail on 13 May 2026: phishing emails posing as payment notices, orders or shipping updates bring a VBS, JavaScript or batch script, which unpacks PowerShell, hides it in a user environment variable, fetches pictures that carry encoded code, and injects the keylogger into aspnet_compiler.exe.
It takes saved passwords, cookies, history and card details from more than 40 browsers, plus keystrokes, screenshots, clipboard and Wi-Fi passwords, and sends them out through a Telegram bot and other servers. Two of the stubs on qpwot.cfd carry this tag.
How do I remove it from Windows?
Disconnect the PC first, and change your important passwords from another device. Then open Windows Security, go to Virus & threat protection, Scan options, choose Microsoft Defender Offline scan and select Scan now. Microsoft says it takes about 15 minutes, restarts the PC and shows results in Protection history.
Afterwards check Task Scheduler, Startup apps and the HKEY_CURRENT_USER\Environment key for leftovers. Because these stealers run in memory and inside real Windows programs, a clean scan does not prove much. If you are not sure, back up your documents and reset Windows with Remove everything from Settings, System, Recovery, Reset PC.
Will resetting Windows remove it, and are my accounts safe afterwards?
A reset with Remove everything reinstalls Windows and deletes apps, settings and personal files, so a stealer that hid in your user profile or startup settings goes with it. Microsoft's page offers cloud download, which fetches a fresh copy of Windows. Back up documents first, and scan the backup before you copy it back.
But a reset does nothing for what was already stolen. Passwords, cookies, card details and Wi-Fi passwords taken before the reset are still in someone else's hands, so change them from a clean device, sign out of all sessions and call your bank about saved cards. The PC and the accounts are two separate jobs.
Can these files infect a Mac, iPhone or Android?
Nothing we read says so. The JavaScript files and PowerShell stubs fit a Windows chain: Windows runs .js and .vbs files with its own script host, and both keyloggers are .NET programs for Windows. A Mac, an iPhone or an Android phone does not run them that way.
If you only use those devices, there is nothing to remove for this threat. If you typed passwords on a Windows PC that may be infected, change them from your phone or Mac, which is the right place to do it anyway.
Why does the front page of qpwot.cfd look harmless?
Our plain request on 6 October 2026 got HTTP 200 through Cloudflare and a page titled Application placeholder. Servers used for malware often show a generic page at the front and keep the real files in folders that only a script knows the path to.
They may also show different things by country, time or software. That is why we never treat a quiet page as a clean result. The rating in this guide comes from URLhaus, which listed seven script files on the same address in eleven minutes, three of them still online when we read the data.
Will Fortect remove qpwot.cfd?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For qpwot.cfd, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- URLhaus (abuse.ch): entries for host qpwot.cfd, as held in our database (read October 6, 2026)
- RDAP record for qpwot.cfd (registered 1 October 2026, Spaceship, Inc.) (read October 6, 2026)
- Microsoft Security Intelligence: Trojan:MSIL/MassLogger.MA!MTB (published 12 November 2020) (read October 6, 2026)
- Microsoft Security Intelligence: Trojan:MSIL/SnakeKeylogger!MSR (published 25 February 2021) (read October 6, 2026)
- Splunk Threat Research: Behind the Code, the layered defense evasion of VIP Keylogger (13 May 2026) (read October 6, 2026)
- Seqrite: VIPKeyLogger, unveiling a multistage keylogger and stealer (white paper) (read October 6, 2026)
- ANY.RUN: MassLogger malware trends (read October 6, 2026)
- Infoblox: MassLogger infostealer malspam campaign (11 August 2020) (read October 6, 2026)
- Security Affairs: new MassLogger variant, research by Cisco Talos (February 2021) (read October 6, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (updated 25 August 2026) (read October 6, 2026)
- Microsoft Support: Help protect my PC with Microsoft Defender Offline (read October 6, 2026)
- Microsoft Support: Reset your PC (read October 6, 2026)
- FTC: How to recognize, remove and avoid malware (April 2025) (read October 6, 2026)