To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.

Malware Overview
This worm spreads by dropping a copy of itself into certain accessible systems in a network. It also spreads by dropping a polymorphed copy of itself upon exploiting Windows vulnerabilities. It uses existing user names on the target system, as well as predefined user names and passwords in order to perform the abovementioned propagation routines.
It is also capable of performing a denial of service (DoS) attack against specific Web sites hardcoded in its body.