Fake Domain Names Trying to Exploit CrowdStrike Vulnerability
Several domain names are expected to be used for recent phishing campaigns.

In the past few days, since the CrowdStrike flaw on Friday (July 19), 67 fraudulent domain names associated with that flaw have been found.
The VisionWare Threat Intelligence Center is warning about "new identity theft campaigns and a new wave of cyberattacks resulting from this incident."
According to CrowdStrike's own statements and those cited by VisionWare, the vulnerability in affected systems still exists, creating an opportunity for cybercriminals to catch the moment.
The CrowdStrike flaw is being used by cybercriminals to gain economic advantages, as fraud schemes are already visible through malicious fake file updates.
Therefore, VisionWare emphasizes that "it is increasingly important to have stricter rules and procedures applied to manufacturers, just as they are in quality processes for other manufacturers."
A source from VisionWare's Threat Intelligence Center, which is a global threat monitoring center, said to IT Security, "These data only confirm what we all feared but already had: the increase of social engineering maneuvers that take advantage of the instability felt by the companies targeted by this blackout. We will certainly face a new and intense wave of cyberattacks related to this incident."
"There are 8.5 million infected computers, and most of them remain unresolved. This is, first of all, an important period for the attackers to implement new plans that allow them to reach their targets, meaning that the authorities responsible will have to carefully investigate and search for answers. This is a slow and comprehensive process that requires a lot of awareness and preparation," said the same source.
The currently defined fake domain names are as follows:
- crowdstrike-bsod[.] co
- crowdstrike-bsod[.] with
- crowdstrike-fix[.] Zip
- crowdstrike-helpdesk[.] with
- crowdstrike-out[.] with
- crowdstrike[.] blue
- crowdstrike[.] bot
- crowdstrike[.] Cam
- crowdstrike[.] Ee
- crowdstrike[.] Es
- crowdstrike[.] Fail
- crowdstrike0day[.] ile
- crowdstrikebluescreen[.] ile
- crowdstrikebsod[.] Co
- crowdstrikebsod[.] ile
- crowdstrikebug[.] ile
- crowdstrike iddiası[.] ile
- CrowdstrikeClaims[.] ile
- CrowdstrikeClassAction[.] ile
- Crowdstrikecure[.] ile
- CrowdstrikeDoomsday[.] ile
- Kalabalık grevi[.] ile
- crowdstrikedown[.] site
- crowdstrikefail[.] with
- crowdstrikefix[.] co
- crowdstrikefix[.] with
- crowdstrikefix[.] In fashion
- crowdstrikefix[.] Zip
- crowdstrikeglitch[.] with
- crowdstrikehelp[.] with
- crowdstrikelawsuit[.] with
- crowdstrikemedaddy[.] with
- crowdstrikeold[.] with
- crowdstrikeoops[.] with
- crowdstrikeoopsie[.] with
- crowdstrikeoopsies[.] with
- crowdstrikeout[.] with
- crowdstrikeoutage[.] with
- crowdstrikeoutage[.] Info
- crowdstrikepatch[.] with
- crowdstrikeplatform[.] with
- crowdstrikeplatform[.] Info
- crowdstrikerecovery[.] with
- crowdstrikereport[.] with
- crowdstrikesettlement[.] with
- crowdstrikesupport[.] with
- crowdstrikesupport[.] Info
- crowdstriketoken[.] with
- crowdstrikeupdate[.] with
- crowdstrikeyou[.] Xyz
- crowdstrikezeroday[.]com
- fix-crowdstrike-apocalypse[.]com
- fix-crowdstrike-bsod[.]com
- fix-crowdstrike[.]com
- fixcrowdstrike[.]com
- fixmycrowdstrike[.]com
- fuckcrowdstrike[.]com
- howtofixcrowdstrikeissue[.]com
- iscrowdstrikedown[.]com
- iscrowdstrikefixed[.]com
- iscrowdstrikestilldown[.]com
- isitcrowdstrike[.] with
- microsoftcrowdstrike[.] with
- microsoftoutagescrowdstrike[.] with
- secure-crowdstrike[.] with
- supportcrowdstrike[.] with
- whatiscrowdstrike[.] with
Source: Fraudulent Domains Seek to Take Advantage of CrowdStrike Flaw (itsecurity.pt)