It uses the following list of domain names to compose the fake address:
- @dailymail.co.uk
- @mail.com
- @aol.com
- @hotmail.com
- @gmx.net
- @t-online.de
- @yahoo.co.uk
- @msn.com
- yahoo.com
- cox.net
The worm downloads a backdoor from one of websites and activates it. The backdoor is known as 'Surila.I' or 'BackDoor-CEB.c' and is downloaded from the following websites: