FreeCupHolder.com — CupHolder XP
FreeCupHolder.exe
Malware Museum
?
Would You Click It?
!
Modern Threats
The Art of the Con
Security Checklist
Security Glossary
FAQ.txt
!
Security Bulletins
Internet Resources
@
Contact Us
My Computer
Recycle Bin
Welcome to CupHolder XP
CYBERSECURITY AWARENESS PROJECT
FREE CUP HOLDER .exe → .edu
In the late '90s, a tiny executable promised you a free cup holder. It opened your CD-ROM tray. Hilarious? Sure. But it was also one of the internet's first lessons in social engineering — and the threats have only evolved.
// What the user saw:
C:\> FreeCupHolder.exe
Congratulations! Deploying your FREE cup holder...
// What actually happened:
→ DeviceIoControl(IOCTL_STORAGE_EJECT_MEDIA)
→ CD-ROM tray opens
→ User stares at tray. Places coffee on it. Regrets.
The cup holder gag worked because people trusted executables from strangers. No code signing, no sandboxing, no SmartScreen, no EDR. You got an .exe from a friend-of-a-friend on IRC and you ran it. The joke was benign. The habit was lethal.
3.4B
phishing emails / day
$4.9M
avg breach cost
258
days avg detection
68%
breaches: human element
Where do you want to be fooled today? (Nowhere. That's the training.)
▶ Run FreeCupHolder.exe Tour the Malware Museum Take the phishing quiz Harden your business
Pro tips from the sysadmin: leave the machine idle for a while. Try Start ▸ Turn Off Computer. The shield in the tray does a free checkup. None of it will hurt. Probably.
A production of Pendergrass Consulting — Selma, NC. From prank to paradigm.
FreeCupHolder.exe — Setup Wizard
Welcome to the FreeCupHolder Setup Wizard
This wizard will deploy one (1) complimentary beverage receptacle to your workstation. No payment required. No questions asked. Especially no questions asked.
It is recommended that you close all running skepticism before continuing.
Publisher: A Friend Of A Friend On IRC (unverified)
Certificate: none · Reviews: "lol run it" (14,882)
< Back Next > Cancel
License Agreement
Please read the following carefully. (You won't. That's the exhibit.)
CUP HOLDER END-USER LICENSE AGREEMENT (v1.997)
1. The Software will deploy one (1) complimentary beverage receptacle.
2. The receptacle is your CD-ROM tray. It was always your CD-ROM tray.
3. By clicking "I Agree" you confirm that you did not read this agreement, which is Exhibit A in why this website exists.
4. You agree to hover before you click, verify before you trust, and never run executables from strangers again. This clause is legally unenforceable and morally binding.
5. Warranty: the tray holds one (1) beverage for up to four (4) seconds of confidence. No beverages were harmed in the making of this software. Your keyboard's luck may vary.
< Back I Agree — Install Cancel
Deploying beverage infrastructure…
{{ instLine }}
Tip: real installers show a publisher and a signature here. This one shows vibes.
Cancel
Setup complete.
It is now safe to place your beverage. Your cup holder has been deployed to the lower-right corner of the screen.
In 1997, thousands of people ran a stranger's .exe for exactly this payoff. The joke was harmless. The habit wasn't — 71% of targeted attacks still start with a person clicking something they shouldn't.
Every link, attachment, and download is a trust decision. Make it deliberately.
Would you have clicked it? Take the quiz Finish
FreeCupHolder Security — Checkup
Quick Security Checkup
Definitely not a real antivirus. The findings, however, are real enough.
Scan now
{{ scPath }}
⚠ {{ f }}
Scan complete — 4 items found. Real security is a practice, not a scan: patch, train, monitor, repeat. Recommended action: open the Security Checklist.
Open Security Checklist
The Art of the Con — A Field History of Social Engineering
{{ g.era }}
{{ it.label }}
{{ it.label }}
CON {{ conNo }}
{{ conName }}
Era: {{ conYear }} Levers pulled: {{ lv }}
{{ conPitch }}
{{ conStory }}
Same con, current wrapper: {{ conToday }}
Fifty years, six levers: authority · urgency · fear · greed · curiosity · trust. Software got patched. People got busier.
Malware Museum — 30 Years of the Same Trick
{{ g.era }}
{{ it.label }}
{{ it.label }}
EXHIBIT {{ mNo }}
{{ mName }}
Year
{{ mYear }}
Class
{{ mType }}
Vector
{{ mVector }}
Damage
{{ mDamage }}
{{ mStory }}
Lesson: {{ mLesson }}
Every exhibit is the cup holder again: a human made a trust decision without verifying.
Would You Click It? — CupHolder Mail
ReplyReply AllForwardMark as: your call ↓Inbox — 6 messages, 6 suspicious (statistically)
! · From · Subject
{{ e.status }}{{ e.from }}
{{ e.subj }}
{{ e.status }}{{ e.from }}
{{ e.subj }}
Two of these are legitimate. Four want your credentials, your gift cards, or your dignity.
Message {{ qN }} of 6
From: {{ qFrom }} <{{ qAddr }}>
Subject: {{ qSubj }}
{{ ln }}
Your verdict: ✓ Legitimate ⚠ Phishing
Correct — this was {{ qTruth }}. {{ qWhy }}
Not quite — this was {{ qTruth }}. {{ qWhy }}
{{ qNextLabel }}
SCAN OF USER COMPLETE
{{ qScore }} / 6
{{ qGrade }}
{{ qGradeNote }}
Try again Book real training for your team
Modern Threats — Security Center
Same trick, new wrapper
FreeCupHolder.exe exploited curiosity and trust. That was 1997. In 2026 attackers run the exact same playbook — with AI, deepfakes, and your whole digital footprint. The only difference is the sophistication of the convince.
{{ t.sev }} {{ t.t }} {{ t.arrow }}
{{ t.body }}
Every one succeeds the same way: convince a human to do something they shouldn't. Train the human. Harden the system. Verify everything.Get help
My Services — Add or Remove Programs
Currently installed services
Pendergrass Consulting
Selma, NC
Small-business IT done right — without the enterprise price tag. Click an entry for details. Sort by: Usefulness ▾
{{ s.n }} Size: {{ s.size }}
{{ s.desc }}
Used: frequently · Publisher: verified (an actual one)AddRemove
# Ready to secure your business? → We respond within 24 hours. No sales pitch, just honest advice.contact.exe
Security Glossary — Help and Support
CONTENTS — 16 TERMS
? {{ g.t }}
? {{ g.t }}
{{ glTerm }}
{{ glDef }}
Field note: {{ glNote }}
Internet Resources — CupHolder Explorer
Address http://freecupholder.com/resources — tools, frameworks and knowledge Go
Arm yourself with knowledge
Every link below is real and leaves the museum. That is the joke: on this site, the trustworthy links look boring.
01 — FRAMEWORKS & STANDARDS (START HERE)
NIST Cybersecurity Framework 2.0
The gold standard: Govern, Identify, Protect, Detect, Respond, Recover — any size business.
CISA — Cybersecurity & Infrastructure Security Agency
Free advisories, incident-response resources, and the Known Exploited Vulnerabilities catalog. If it's being exploited, CISA knows first.
CIS Controls v8
Prioritized, actionable controls. Implementation Group 1 is designed for small businesses with limited IT. Start there.
OWASP Top 10
The definitive list of critical web-application risks. Essential if you build or maintain web apps.
02 — ESSENTIAL TOOLS
Bitwarden / 1Password — password managers
Unique, complex passwords for every account. If you can remember your password, it isn't strong enough.
YubiKey — hardware MFA
FIDO2 hardware keys are phishing-resistant. Authenticator apps are not. SMS is barely trying.
Have I Been Pwned
Check if your email appears in known breaches. Subscribe. Enable domain-wide monitoring for your business.
Pi-hole / NextDNS / Quad9 — DNS filtering
Block malicious domains before the browser ever connects. Zero user interaction required.
Security Onion — free SIEM & threat hunting
Full-packet capture, Suricata, Zeek, Elasticsearch and Kibana in one deployable ISO.
03 — LEVEL UP
TryHackMe
Hands-on, browser-based security labs. Gamified learning that actually works.
SANS Cyber Aces
Free introductory courses: operating systems, networking, sysadmin — the bedrock of security knowledge.
Krebs on Security
Investigative reporting on cybercrime. Deep dives on breaches, threat actors, and attack infrastructure.
Need help implementing any of these? We deploy, configure, and manage security infrastructure for small businesses. Get in touch →
Done🔒 12 items — all safe to click. Refreshing, isn't it?
FAQ.txt — Notepad
FileEditFormatHelp
=== FAQ.txt — FreeCupHolder.com === Q: What was FreeCupHolder.exe? A: A late-'90s prank program. It promised a free cup holder, then ejected your CD-ROM tray. The payload was harmless. The habit it exposed — running strangers' executables on faith — was not. Q: Will this website eject my actual CD tray? A: Only the simulated one. Modern browsers cannot touch your hardware, which is exactly the kind of progress we are celebrating. (Also, your laptop probably has no tray. Pour one out.) Q: Who runs this site? A: Pendergrass Consulting, an IT consulting firm in Selma, North Carolina, serving small businesses across the NC Triangle and nationwide. FreeCupHolder.com is our awareness project. Q: Is this thing collecting my data? A: No. The quiz, checklist, and scanner run entirely in your browser. Nothing you click here is transmitted anywhere. We are building the OPPOSITE instinct. Q: What is social engineering? A: Convincing a human to do something they shouldn't — click, download, approve, wire, whisper. Every era in the Malware Museum is the same trick in a new wrapper. See: Security Glossary. Q: How do I report a phishing email? A: Use your mail client's Report Phishing button, forward it to your IT or security team, and report to reportphishing@apwg.org or cisa.gov/report. Then delete it. Don't reply. Don't click. Don't "just check". Q: My business needs actual help. Do you do that? A: Yes. Pen testing, managed IT, security training, infrastructure, OSINT, web development. Open "My Services" on the desktop, or Contact Us — we respond within 24 hours. Q: Why does this site look like it's from 2001? A: Because the lesson is. The cup holder worked in 1997 and the same psychology works today. We just gave the museum period-correct walls. Q: Can I get an actual free cup holder? A: Press the eject button on a 1998 Gateway tower. Everything since has been downhill.
Small Business Security Checklist
Protection level: {{ clLevel }}
{{ clCount }} of 10 complete — progress saves on this machine
{{ clPct }}%
Stuck below 10? This list is our day job — deployment, configuration, and the training to make it stick.Call for backup
Security Bulletins — freecupholder.com/advisories
What we're telling clients this quarter. Same pattern since 1997 — only the wrapper changes. Click a bulletin to expand.
{{ a.sev }} {{ a.id }} {{ a.title }} {{ a.date }}
{{ a.body }}
New Message — CupHolder Mail
▶ Transmit AttachSpell Response within 24 hours. No sales pitch, just honest advice.
To:Pendergrass Consulting — via freecupholder.com secure relay Your name: * Your email: * Organization: Inquiry type: *
One checkbox between you and the mail server. The 1997 version of this site would have skipped it — that's the point of this site.
$ whois pendergrass-consulting
Organization: Pendergrass Consulting
Address: 110 S. Massey St., Suite 201, Selma, NC 27576
Service area: NC Triangle & Nationwide · Web: pendergrassconsulting.com
Response: within 24 hours
Protected by Cloudflare Turnstile. Disposable email addresses are rejected — we check ours, you should check yours.
start
{{ t.label }}
{{ t.label }}
! 🔇🔊 {{ clock }}
Guest (you, presumably)
eInternet
Curated security resources
@E-mail
Contact Pendergrass Consulting
CHFreeCupHolder.exe
MMalware Museum
?Would You Click It?
!Modern Threats
SEThe Art of the Con
Security Checklist
All Programs
Welcome Tour
My Services
Security Bulletins
Security Glossary
Security Checkup
Help and Support
Run…
Log Off Turn Off Computer
!Your beverage might be at risk
FreeCupHolder Security recommends a quick checkup. It found the scan button and would like to press it. Click this balloon to comply.
CUP-ROM™ 52X MAX BEVERAGE BAY 1 ⏏ eject
PLACE
BEVERAGE
HERE
holds 1 (one) beverage · confidence: 4 seconds
{{ dlg.t }}
i
{{ dlg.b }}
OK
A problem has been detected and CupHolder XP has been shut down to prevent damage to your beverage.
CUP_HOLDER_OVERFLOW_EXCEPTION
If this is the first time you've seen this Stop error screen, place your drink somewhere stable and restart. If this screen appears again, follow these steps:
Check that any new hardware or beverages are properly seated. Never run executables from strangers, even charming ones. Enable MFA, patch your systems, back up your files, and question everything.
Technical information:
*** STOP: 0x0000C0FFEE (0x00000019, 0x00000097, 0xDECAF000, 0x00000000)
*** cupholdr.sys — Address DECAF000 base at C0FFEE00, DateStamp 1997
Beginning dump of physical coffee...
Physical coffee dump complete.
Click anywhere (or press any key) to restart _
Turn off computer
After you log on, question everything. Especially free peripherals.
Pendergrass Consulting
CupHolderXP
FREE BEVERAGE EDITION
Copyright © Pendergrass Consulting, Selma NCFor best results, never run executables from strangers