Internetnews: "The sadmind/IIS worm propagates from an infected Solaris machine by probing port 80 on a random Class B set of IP addresses, looking for the
signature of other Solaris or IIS web servers. Should it find another vulnerable Solaris machine, the worm will upload its attack tool, root.exe, and
infect the server."
May 9, 2001