A page at discord-eu[.]cfd impersonates Discord and displays a fake Cloudflare human-verification prompt. Instead of using a normal checkbox, the page tells the visitor to press Win + R, paste a command with Ctrl + V, and press Enter. The supplied command uses PowerShell's encoded-command option, which can hide what will run and may download malware or execute other harmful instructions.
A page uses Discord branding and a Cloudflare-style verification box to appear trustworthy.
A dialog says the visitor must complete an Anti-Bot check and instructs them to press Win + R, paste text, and press Enter.
The pasted text launches PowerShell with an encoded command instead of showing the visitor what will run.
The hidden command can download or execute harmful content on the Windows computer.
✓ Do this
✗ Avoid this
Do not reply, pay, or use contact details in an unexpected message. Verify through the official app or website, then report what you saw so the Archive can connect related patterns.
Don’t call numbers or click links in unexpected messages. Go directly to the company’s official site or app and contact support from there.