It uses the following list of last names to compose the fake address:
- Smith
- Johnson
- Williams
- Jones
- Brown
- Davis
- Miller
- Wilson
- Moore
- Taylor
- Anderson
- Thomas
- Jackson
- White
- Harris
- Martin
- Thompson
- Garcia
- Martinez
- Robinson
- Clark
- Rodriguez
- Lewis
- Lee
- Walker
- Hall
- Allen
- Young
- Hernandez
- King
- Wright
- Lopez
- Hill
- Scott
- Green
- Adams
- Baker
- Gonzalez
- Nelson
- Carter
- Mitchell
- Perez
- Roberts
- Turner
- Phillips
- Campbell
- Parker
- Cruz
- Marshall
- Ortiz
- Gomez
- Murray
- Freeman
- Wells
- Webb
- Simpson
- Stevens
- Tucker
- Porter
It uses the following list of domain names to compose the fake address:
- @dailymail.co.uk
- @mail.com
- @aol.com
- @hotmail.com
- @gmx.net
- @t-online.de
- @yahoo.co.uk
- @msn.com
- yahoo.com
- cox.net
Downloading a backdoor
The worm downloads a backdoor from one of websites and activates it. The backdoor is known as 'Surila.I' or 'BackDoor-CEB.c' and is downloaded from the following websites:
- www.planetboredom.net
- vugs.geog.uu.nl
- www.ach.ch
- www.hiw.kuleuven.ac.be
- www.surrenderzeeland.nl
- www.llc.unibo.it
Limited lifecycle
After September 20th, 2004, 01:18:31 the worm stops working and deletes its file from a hard drive.