Crypted.ps1. The other two were JavaScript files with long random names. Three of the entries carried the VIPKeylogger tag. VIP Keylogger is a Windows stealer that records keystrokes and takes passwords.Before anyone panics: the domain is now dead, and seeing its name in a log doesn't prove a PC was infected. If a script on a Windows PC actually downloaded and ran one of these files, though, the order of your next steps matters. This article covers what's known, what isn't, and how to respond.
What URLhaus recorded, and when
2-Spyware built this timeline from its copy of the URLhaus data and from RDAP domain-registration records. All times are UTC:
- 21 September 2026, about 12:18: cablewireltd.site was registered through Spaceship, Inc. The name sounds like a cable-and-wire supplier, which is a common way to make a malware host look like a business.
- 23 September, about 08:09–08:10: Five files were added.
Crypted.ps1appeared in folders namedmasabik23,mrprinceandmasfrnd, and two long-named.jsfiles appeared inppriincefil21. Themasabik23file was tagged VIPKeylogger. All five carried theopendirtag, meaning anyone could list the folder contents. - 23 September, about 13:59: Three more
Crypted.ps1paths appeared, inprince23,masabik232andmassfrnd232. Themasabik232file was tagged VIPKeylogger. - 24 September, about 13:41: The last file,
Crypted.ps1infrndmass244, was added and tagged VIPKeylogger. - 10 October 2026: All nine entries were marked offline. RDAP showed the domain on server hold, a registry-level status that removes a domain from DNS. A lookup from 2-Spyware's server failed with
getaddrinfo ENOTFOUND.
What this evidence doesn't prove: 2-Spyware says it didn't download or open any of the files. Nobody has published an analysis of these nine samples, so the VIP Keylogger link rests on URLhaus tags, not reverse engineering. The outlet also suggests the folder names (prince, mrprince, masabik and so on) are labels for different customers or campaigns of one operator. That's its own guess, not a confirmed attribution.
Summary: One short-lived domain hosted nine malware files over about 48 hours, three of them tagged as a known Windows stealer, and was then pulled offline.
What VIP Keylogger does once it runs
The family itself is well documented. In May 2026, Splunk's Threat Research Team published an analysis of the malware. The team reviewed more than 200 loader samples collected in March and April 2026, documenting their naming patterns, loader variants, and the steganographic use of PNG files for payload delivery.
The infection chain has several steps:
- Lure. Attackers send phishing emails disguised as bank payment notifications, procurement orders, and logistics updates.
- Script loader. Its infection chain relies on malicious VBS, JavaScript, or batch-based loaders that use heavy obfuscation, steganography in PNG images, and abuse of environment variables to conceal PowerShell stages before launching the final keylogger.
- PowerShell stages. In the JavaScript variant Splunk analyzed, the obfuscated
.jsfile fetches a PowerShell stager. This is the layer a file namedCrypted.ps1would plausibly fill. 2-Spyware describes such a file as a middle step that does nothing unless something already on the PC downloads and runs it. - Hiding inside a trusted process. In Splunk's sample, a .NET module injects the VIP Keylogger, into a legitimate aspnet_compiler.exe process using "Invoke-AssemblyExecution" Function. In Task Manager, the stealer then appears under a Microsoft name.
- Persistence. One batch-file variant secures persistence by hijacking the "UserInitMprLogonScript" registry key. By planting its file path here, the malware ensures it's triggered automatically every time the user logs in.
Splunk's analysis also lists what the stealer takes:
- saved browser passwords, cookies, autofill data and card details
- Discord tokens and Outlook credentials stored in the registry
- every keystroke
- periodic screenshots, saved to a
VIPRecoveryfolder under Documents - saved Wi-Fi passwords, pulled with
netsh wlan show profile ... key=clear - cryptocurrency wallet addresses copied to the clipboard, which it swaps for an attacker's address
The data leaves through several command-and-control channels, including a Telegram bot.
One caveat: this is family-level context from samples Splunk analyzed, not from cablewireltd.site. Nobody has shown that this domain's files used this exact chain, these file paths or this registry key.
Summary: VIP Keylogger uses layered loaders, runs hidden inside a trusted process and takes nearly everything stored on the PC. That's why the cleanup order below matters.
Saw the name in a log? Here's how to read it
| What you saw | What it likely means |
|---|---|
| A DNS, firewall or proxy entry for cablewireltd.site | Something tried to look up or contact the name. On its own, that's not proof of infection. |
| A browser or SmartScreen warning | The block probably worked. Check what triggered the request. |
A downloaded Crypted.ps1 file, a script you ran, or an endpoint alert | Treat the PC as possibly compromised. |
| Persistence clues (see below) alongside any of the above | Strong evidence. Escalate. |
As 2-Spyware notes, an ordinary visitor has no reason to request a file called Crypted.ps1. The reverse also holds: a dead domain today tells you nothing about a PC that fetched a file in September. Operators can also move the same files to a new domain within hours.
If a script really ran: what to do, in order
Step 1: Secure your accounts from a different device
Start here, before you clean the PC. A stealer may already have sent your credentials, and removing the malware doesn't take them back. On a phone or another computer you trust:
- change passwords for email, banking, work and other important accounts
- sign out of all sessions where the service offers it, so stolen cookies stop working
- turn on two-step sign-in
- contact your bank about any saved cards
- if you hold crypto, check any recent transactions where an address was pasted
Step 2: Look for leads (and don't delete in a hurry)
2-Spyware suggests checking these places, based on Splunk's findings:
- Registry: in
HKEY_CURRENT_USER\Environment, look for aUserInitMprLogonScriptvalue. - Files: look in
%appdata%\Microsoft\Windows\Librariesfor script files that aren't library files, and in Documents for aVIPRecoveryfolder. - Startup: check Settings > Apps > Startup for apps you didn't install.
- Scheduled tasks: in Task Scheduler Library, look for tasks that run PowerShell, wscript, or a script stored in a user folder.
Treat anything you find as a lead to record before you change it. None of these is proof by itself. Legitimate admin tools can set logon scripts, and many real tasks have odd names.
Step 3: Run a full scan, then Microsoft Defender Offline
In Windows Security > Virus & threat protection > Scan options, run a Full scan first. Then select Microsoft Defender Offline scan and click Scan now.
Microsoft's documentation says the offline scan starts from a trusted environment outside the normal Windows kernel, so malware running inside Windows has a harder time hiding from it. You can also start it from an elevated PowerShell prompt:
Start-MpWDOScan
Microsoft lists these requirements and warnings for the offline scan:
- Supported hardware: x64 Windows 11 and x64/x86 Windows 10. It doesn't work on ARM editions of Windows 10 or 11, or on Windows Server SKUs.
- WinRE must be enabled. If the Windows Recovery Environment is off, the scan simply doesn't run and shows no error. To check, run
reagentc /infofrom an administrator Command Prompt. To turn it on, runreagentc /enable. - Local administrator rights are required.
- BitLocker: suspend protection first. Otherwise the restart may ask for your recovery key.
- Updates: the offline scanner only gets updates when Microsoft Defender Antivirus is your primary antivirus, not running in passive mode.
- Time: save your work first. The scan takes about 15 minutes and restarts the PC.
What success looks like: after the reboot, check Protection history in Windows Security. In Event Viewer, under the Windows Defender Operational log, Event ID 2030 confirms the offline scan was set up to run on the next restart. If malware keeps coming back after each restart, Microsoft says a hidden component is probably reinstalling it, which is exactly the case the offline scan is meant for.
Step 4: If in doubt, reset
A clean scan is reassuring, but it isn't proof. Use Settings > System > Recovery > Reset this PC. For a machine that ran a stealer, 2-Spyware recommends Remove everything, because that option doesn't depend on finding every leftover piece. Back up your documents first.
Microsoft also advises restoring from backups made before the infection and stored off the PC. Backups kept on the machine may already have been tampered with.
For admins: what to hunt for
Splunk's detections focus on behaviors, not file names. That matters here, because the next domain won't be called cablewireltd.site and the next file may not be called Crypted.ps1. Recommended controls include:
- watching for changes under
HKCU\Environment, especially very large values or theINTERNAL_DB_CACHEvariable - restricting scripts that run from user-writable folders
- enforcing PowerShell Constrained Language Mode where you can
- flagging injection into
aspnet_compiler.exeand suspiciousnetshactivity
Splunk's analytic story also notes that VIP Keylogger overlaps heavily with Snake Keylogger. Hunting for .NET tools launched by scripts can catch several related families at once, not just one file hash.
The bottom line
cablewireltd.site was a disposable malware host. It was registered on a Sunday, serving tagged payloads by Tuesday, and on server hold by mid-October. Blocking the domain now is mostly a formality. What matters is behavior-based defense and responding in the right order. If you only saw the name in a log, investigate calmly. If a script ran, change your passwords from another device first, then clean the PC, and reset Windows if you're not sure it's clean.
References
- cablewireltd.site: VIP Keylogger PowerShell Host, Removal - 2-Spyware 2-Spyware · 2026-10-10T14:08:32.145000+00:00
- Behind the Code: The Layered Defense-Evasion of VIP Keylogger | Splunk splunk.com
- Analytics Story: VIP Keylogger | Splunk Security Content research.splunk.com