Seems like McDonald’s and Coca-Cola are cybercriminals’ promoters of choice this season–two spoofed emails that claim to be from both of the highly popular brands were recently found by the Trend Micro Content Security Team.
Each message trumpets a Christmas promotion, and instructs the recipient to open the attached coupon contained in a .ZIP file.
Below are some sample screenshots:

Figure 1. Spammed message purported to come from Coca Cola

Figure 2. Attached file which supposedly contains information in the promo

Figure 3. Another spammed message, this time purported to be from McDonald’s

Figure 4. Attached file which poses as a coupon
Trend Micro already blocks such messages, and detects both attached files through the Smart Protection Network as WORM_MYDOOM.CG. This worm gathers email addresses from the affected system’s Windows Address Book and then sends copies of itself via email, using its own SMTP engine. It also drops copies of itself in folders shared in peer-to-peer networks, as well as in all physical removable drives. Furthermore, it drops a file detected as BKDR_SDBOT.QB.
This new twist in the way victims are lured into this scheme, which was initially seen just last week, strongly suggests that cber criminals are really getting their creative juices flowing, especially now that the holiday season is in full swing. On that note, users are advised to keep an eye out for these malicious schemes, and to not open unsolicited mails, as tempting as their offerings may be.
If you're new here, you may want to subscribe to our RSS feed. Thanks for visiting!



December 3rd, 2008 at 7:54 pm
Email Spam Scams: Spoofing as Ronald McDonald & Coca Cola, creative criminals are trying to steal your information http://bit.ly/111it
December 4th, 2008 at 6:59 am
[...] een variant van de Sdbot, waarmee de aanvaller volledige controle over het systeem krijgt. Volgens virusbestrijder Trend Micro is de "nieuwe aanpak" teken dat cybercriminelen met de [...]
December 4th, 2008 at 6:05 pm
[...] – Trendlabs MALWARE Blog - McAfee Avert Labs [...]
December 5th, 2008 at 5:43 pm
[...] MYDOOM.CG Worm – Dangerous and realistic holiday email promotionhttp://blog.trendmicro.com/bogus-mcdonalds-coca-cola-promos-used-as-worm-carriers/http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MYDOOM.CGhttp://www.trendmicro.com/vinfo/images/WORM_MYDOOM_CG_BD.gif [...]