The Spread of the Code-Red
Worm (CRv2)
Overview
On July 19, 2001 more than 359,000 computers
were infected with the Code-Red (CRv2) worm in less than 14 hours.
At the peak of the infection frenzy, more
than 2,000 new hosts were infected each minute. 43% of all infected hosts
were in the United States, while 11% originated
in Korea followed by 5% in China and 4% in Taiwan. The .NET Top
Level Domain (TLD) accounted for 19% of all
compromised machines, followed by .COM with 14% and .EDU with
2%. We also observed 136 (0.04%) .MIL and
213 (0.05%) .GOV hosts infected by the worm. A QuickTime
animation of the geographic expansion of the
worm is available.
Full Story of Analysis http://www.caida.org/analysis/security/code-red/
Animated
gif of geographic spread of Code-Red worm (4.1 MB .gif)
Note:
The animated gif does not display correctly in all browsers.
SANS Security Alert. Code Red Is Set to Come
Storming Back!
See
Info from SANS 07/29/2001
Some Worm History
The
Morris Internet Worm Brief history of the Worm
The
What, Why, and How of the 1988 Internet Worm
The
Internet Worm