McDonald’s Phishing Message Brings All-You-Can-Eat-Malware
BUCHAREST, Romania  - June 21, 2011 - A tasty McDonald's free menu is enough of a bait for lots of starving fellows, and is now the latest spam trap spreading across the Web. According to BitDefender®, an award-winning provider of innovative internet security solutions, the most recent gastronomic spam trap looks is being received in users’ inboxes as an invitation to order  a  five dish meal –  free of charge at the nearest McDonalds’s hot spot.
The subject tag lines used are appealing and convincing to the public. Subject lines being used are: “We invite everyone to the day of free food,” “We will feed you for free” or “Tasty and free food for each visitor.”

Pag.1 Spam e-mail with tempting “We invite everyone to the day of free food” subject line

The message comes from various senders and looks to originate from the mcdonalds.com servers, however it comes from a third-party server that has been heavily involved in spam operations in the past. Other senders for this campaign are assistance@mcdonalds.com, help@mcdonalds.com, helping@mcdonalds.com, manager@mcdonalds.com or support@mcdonalds.com.

If the user follows the instructions enclosed in the message, they will find an archived exe file with an icon mimicking  a Microsoft Word document. This binary file is a downloader Trojan, identified by BitDefender as Trojan.FakeAV.LSX which connects to a series of websites and tries to download other malicious files - including a backdoor and a variant of Kazy – on the already-compromised computer.

Any user running a BitDefender product on your computer, will not be exposed to this e-threat as BitDefender Lab has been identifying this e-threat using a generic signature.

All product and company names mentioned herein are for identification purposes only and are the property of, and may be trademarks of, their respective owners.

Share this post

Submit to Delicious Submit to Digg Submit to Facebook Submit to Google Bookmarks Submit to Stumbleupon Submit to Technorati Submit to Twitter Submit to LinkedIn