Yup. Before they just blackholed Finnish IP ranges instead, accessing the site from one would serve a fake Cloudflare page with a reCAPTCHA challenge and the DDoS script. (The tell of it being fake is y'know, that Cloudflare doesn't use reCAPTCHA)
I can only guess the goal was to keep users on that page longer to keep sending off more spam requests.