Code Red II is a computer worm first released on August 4, 2001, roughly two weeks after the original Code Red outbreak. Although it used the same Microsoft IIS exploitation vector as Code Red, analysis determined it was a distinct worm rather than a simple variant. It targeted vulnerable Microsoft Internet Information Server (IIS) systems by exploiting a flaw in IIS indexing software identified in the content as CVE-2001-0500 and referenced via Microsoft bulletin MS01-033. Infection attempts commonly appeared in web logs as requests to /default.ida carrying a long encoded payload; related reporting also notes use of repeated 'X' characters in the overflow string.
Unlike the original Code Red worm, Code Red II did not include the same denial-of-service attack function. Its payload instead installed a backdoor that enabled subsequent attacks on compromised hosts. The worm also differed in propagation behavior: rather than scanning the internet uniformly at random, it preferentially attempted to infect systems on the same subnet as an already infected machine, while still using pseudo-random target selection biased toward the local subnet.
The content describes Code Red II as a server-jamming worm and places it in the 2001 worm wave alongside Code Red, Klez, and Nimda. Many IIS servers remained unpatched despite Microsoft having released a fix on June 18, 2001, and reporting cited in the content states that even some Microsoft servers were infected or unpatched. Code Red II is also notable because later malware, including Nimda, spread via backdoors left behind by Code Red II. The content references analyses by Steve Friedl and eEye Digital Security, and one source cited in the material assessed a possible origin in Makati, Philippines, though that attribution is not established as definitive.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The worm was designed to exploit a security hole in the indexing software included as part of Microsoft's Internet Information Server (IIS) web server software (CVE-2001-0500). | Code Red II is a computer worm similar to the Code Red worm. Released two weeks after Code Red on August 4, 2001, it is similar in behavior to the original, but analysis showed it to be a new worm instead of a variant. Unlike the first, the second has no function for attack; instead it has a backdoor that allows attacks.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm referenced as leaving backdoors that Nimda later used to spread further.
2001 Anna Kournikova Code Red Code Red II Klez Nimda
Code Red II is referenced as leaving backdoors that Nimda can use to spread further.
A server-targeting worm that exploits a flaw in Microsoft IIS indexing software to infect systems, preferentially spread within the same subnet, and install a backdoor for follow-on attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.