The worm will perform a DDoS attack against on 3rd of February 2004 at 13:09:18 (UTC) and on 1st of February 2004 at 16:09:18 (UTC).

The DDoS attack launches 8 threads against every 1024 milliseconds.

The other DDoS attack launches 14 threads against every 1024 milliseconds.

The hosts file in the infected machines will be modified so that domains belonging to Anti-Virus companies and other commercial sites are resolved to the IP address, rendering them unaccessible.

The full contents of this file follow (The file is encrypted within the worms code):

An additional line is added before the the date when attack against Microsoft begins:

Which will make the site unaccessible. The 3rd of February the entry will be removed so the attack can be performed, which will probably cause some difficulties reaching it, if the DDoS is successful.

The modifications in the hosts file are probably targeted so that customers of the most widespread Anti-Virus products can't download new updates to disinfect the worm.


