Computer Worm
Introduction
Section titled “Introduction”A computer worm is standalone malware that self-replicates and spreads across networks without needing a host file or user interaction. It exploits network vulnerabilities, open shares, or protocols to propagate autonomously, often consuming bandwidth and system resources.
History & Origin
Section titled “History & Origin”| Milestone | Year | Details |
|---|---|---|
| Creeper | 1971 | First worm; ARPANET; “I’m the creeper, catch me if you can!” |
| Morris Worm | 1988 | First destructive worm; 6,000 machines (~10% of internet); first CFAA conviction |
| Code Red | 2001 | 359,000 IIS machines in 14 hours |
| SQL Slammer | 2003 | Global in 10 minutes; 75,000 servers |
| Conficker | 2008 | Millions infected; massive botnet; domain generation |
| WannaCry | 2017 | 200,000 systems in 150 countries; EternalBlue |
How It Works
Section titled “How It Works”1. SCANNING └─ Network scan for vulnerable hosts (SYN scan, ICMP)
2. EXPLOITATION └─ Exploit unpatched service / weak creds / open share
3. COPYING └─ Copy self via exploited channel (SMB, FTP, email)
4. EXECUTION └─ Execute on new host → cycle repeats
5. PAYLOAD DELIVERY └─ Install backdoors, ransomware, DoS
6. C2 COORDINATION (advanced) └─ Contact C2 for updated instructionsNotable Examples
Section titled “Notable Examples”| Worm | Year | Vulnerability | Impact |
|---|---|---|---|
| Morris Worm | 1988 | Unix sendmail/finger | 6,000 machines; CERT/CC created |
| Code Red | 2001 | IIS .ida buffer overflow | 359K in 14 hrs |
| SQL Slammer | 2003 | SQL Server 2000 | 75K in 10 min |
| Conficker | 2008 | MS08-067 | Millions; DGA botnet |
| WannaCry | 2017 | EternalBlue (SMBv1) | 200K in 150 countries |
Prevention
Section titled “Prevention”- ✅ Patch promptly — most worms exploit known, patched vulns
- ✅ Network firewalls — restrict unnecessary connections
- ✅ Network segmentation — VLANs, DMZs limit lateral movement
- ✅ IDS/IPS — detect scanning and propagation
- ✅ Disable unnecessary services and close unused ports
- ✅ Strong passwords + MFA
- ✅ Monitor for traffic spikes / connection volume anomalies
MITRE ATT&CK
Section titled “MITRE ATT&CK”| Technique | ID | Description |
|---|---|---|
| Exploit Public-Facing Application | T1190 | Network service exploitation |
| Lateral Tool Transfer | T1570 | Self-copy to remote systems |
| Command and Control | T1071 | C2 communication |
Related
Section titled “Related”- Computer Virus — Host-attached replication
- Botnet — Coordinated worm armies