SOURCE MATERIAL no. 002 — self-replicating

Ten self-replicating programs, in the order they arrived, told through what they showed the humans: taunts, banners, apologies, love letters, ransom notes, and — where the worm said nothing at all — the numbers it left behind.

Editorial line, held throughout: the specimens on these pages are the messages, filenames, and measured statistics of each outbreak. None of the code that spread them is reproduced here, in any form.

compiled, edited & published by Steven Delpercio · delpercio.dev · 13 July 2026


Creeper

TENEX / ARPANET — 1971

The first program that arranged its own arrival on other machines introduced itself with a taunt — and got the reply it asked for, in the form of a hunter written to delete it.

I'M THE CREEPER : CATCH ME IF YOU CAN

Bob Thomas of Bolt Beranek and Newman wrote Creeper in 1971 as an experiment in moving a running program between machines. It traveled among TENEX systems on the young ARPANET — the network BBN itself operated — packaging its state, hopping hosts, and printing one line of theater on each teletype it visited. Ray Tomlinson, in the same year he sent the first network email, modified it to copy rather than move itself; a colleague's answer, Reaper, stalked the network deleting Creepers.

Nothing about Creeper was hostile: it ran on cooperating systems, under an operating system its authors built, as a demonstration of what they called mobile computation. But the mechanics were the mechanics every later worm would use — find a reachable machine, establish a foothold, resume execution, repeat. The message was the payload, and the payload was a joke.

No listing or output of Creeper survives; the line above is how the participants remembered it, punctuation and all in dispute. That is the right way to meet the lineage: the ancestor of every worm is preserved only as folklore, a sentence passed hand to hand — catch me if you can, addressed to the whole future of the field.


The "Worm" Programs

CACM — 1982

The word 'worm' enters computing: two Xerox PARC researchers name their multi-machine programs after a science-fiction tapeworm and report, candidly, the night one got away from them.

A worm is simply a computation which lives on one or
more machines. The programs on individual computers
are described as the segments of a worm.

                     -- Shoch & Hupp, Communications
                        of the ACM, March 1982

John Shoch and Jon Hupp built worms on purpose. At Xerox PARC in the late seventies they wrote programs whose segments occupied idle Alto workstations by night, cooperating over the Ethernet, growing replacement segments when machines dropped away. The name came from John Brunner's novel The Shockwave Rider; the definition, quoted opposite, came from their 1982 paper in the Communications of the ACM.

Their worms computed for the common good — an alarm-clock service, network measurement, distributed graphics rendering. The paper's most famous passage is a confession: one night a worm was corrupted, and by morning it had crashed dozens of machines and kept crashing them as they restarted. The researchers had built a kill switch, and used it. Worm number one had already escaped intent; it merely lacked malice.

Six years before the Morris worm made the word infamous, this paper supplied the entire conceptual kit: replication, segments, network spread, the control problem, even the emergency stop. When the newspapers of 1988 needed a name for what had swallowed the internet, it was waiting in the academic record — coined by researchers who had hoped worms would be useful.


There may be a virus loose

ARPANET — 1988

The internet's first great outbreak, preserved here as its most human artifact: the anonymous apology and cure, sent at the author's request while the network drowned.

There may be a virus loose on the internet.

Here is the gist of a message I got:

    I'm sorry.

Here are some steps to prevent further transmission:

1) don't run fingerd, or fix it to not overrun its
   stack when reading arguments.
2) recompile sendmail w/o DEBUG defined
3) don't run rexecd

Hope this helps, but more, I hope it is a hoax.

On the evening of 2 November 1988, Robert Tappan Morris, a Cornell graduate student, released a worm from an MIT machine. It entered computers through a debugging feature of the sendmail mailer, an overflow in the finger daemon, and guessed passwords — then, thanks to a misjudged one-in-seven persistence rule, piled copy on copy until machines across the research internet ground to a halt.

In the small hours, Morris's friend Andy Sudduth posted the message shown opposite: anonymous, apologetic, and technically exact, naming all three vectors before most administrators knew what was attacking them. The congestion the worm caused delayed the warning itself — the antidote stuck in traffic behind the poison. Estimates of six thousand infected machines were extrapolations; nobody could count during the flood.

The aftermath built the modern incident-response world: DARPA funded the first Computer Emergency Response Team within the month, and Morris became the first felony conviction under the Computer Fraud and Abuse Act — probation, community service, a fine, and a precedent. The worm's code is studied to this day; its apology is quoted less often, and says more.


Your System Has Been Officially WANKed

DECnet / SPAN — 1989

Days before a plutonium-powered probe left for Jupiter, NASA's science network logged in to a protest: the first worm with a political demand.

W O R M S    A G A I N S T    N U C L E A R    K I L L E R S

        Your System Has Been Officially WANKed

 You talk of times of peace for all, and then prepare
 for war.

On 16 October 1989, machines on SPAN — the DECnet network linking NASA and Department of Energy science sites — began greeting their users with the banner opposite: WORMS AGAINST NUCLEAR KILLERS, wrapped in ASCII art, closing with a line borrowed from the Australian band Midnight Oil. Space Shuttle Atlantis was three days from carrying the Galileo probe, and its plutonium generators, to orbit.

The worm, filed as W.COM, spread through DECnet task objects and default passwords. Its cruelest trick was fiction: it displayed a file-deletion sequence it never performed, so administrators arriving at 'WANKed' machines believed their systems gutted. It changed passwords, it propagated, it postured — protest theater staged in the login sequence of the space program.

Nobody was ever identified; the idiom pointed to Melbourne, and the book Underground later mapped the scene it came from, but attribution stops there. What remains is the precedent: WANK put a cause inside a worm a decade before 'hacktivism' had currency, and every politically framed intrusion since — defacement, leak, wiper — stands in the queue behind this banner.


ILOVEYOU

VBScript / OUTLOOK — 2000

Three lines of longing in an inbox: the outbreak that proved the decisive vulnerability was never in the software.

Subject:     ILOVEYOU

Body:        kindly check the attached LOVELETTER
             coming from me.

Attachment:  LOVE-LETTER-FOR-YOU.TXT.vbs

It left Manila on 4 May 2000 and circled the earth in about a day. The mail said little — a subject line, one coaxing sentence, an attachment named like a love letter — and tens of millions of people found it convincing, because each copy arrived from someone who knew them. Opening the attachment mailed the same letter to everyone in the victim's address book and overwrote their music and photos.

The trick under the trick: Windows hid known file extensions by default, so LOVE-LETTER-FOR-YOU.TXT.vbs displayed as a harmless text file. Mail servers at corporations, parliaments, and defense ministries shut down under the load. The Philippines had no law against what its author had done; charges were dropped, and the country wrote its first computer-crime statute within weeks.

Twenty years later, Onel de Guzman — whose rejected thesis proposal had described stealing passwords — admitted to a journalist that the worm was his. By then his three lines had become the founding text of a genre that never stopped working: the attack that asks the reader to want the message to be true. Damage was estimated in billions; the estimates, like the love, were approximate.


Hacked By Chinese!

IIS / HTTP — 2001

The worm that defaced the web at scale — and the first outbreak scientists watched live, plotted, and timed to the minute.

HELLO! Welcome to http://www.worm.com!
Hacked By Chinese!

--

measured, 19 July 2001 (CAIDA):
  359,000+ hosts infected in under 14 hours
  peak: more than 2,000 new hosts per minute
patch available since 18 June 2001 (MS01-033)

Visitors to hundreds of thousands of websites in July 2001 met the greeting opposite instead of the page they wanted. Code Red lived entirely in the memory of Microsoft IIS servers, entering through a buffer overflow in an indexing extension that had been patched a month earlier. Researchers at eEye Digital Security named it for the caffeinated soda that fueled the disassembly.

Its second version, released 19 July, carried a working random scanner — and the internet's measurement community was, for the first time, ready. CAIDA's monitors counted more than 359,000 infections in under fourteen hours and published the growth curve: the textbook S-shape of an epidemic, drawn by real traffic. The worm's calendar-driven payload, a flood aimed at the White House website's address, was defeated by moving the address.

The defacement's taunt implied an origin no evidence established; the author was never found. What endured was the method of watching: Code Red made outbreak epidemiology a discipline with data, and its curve — reproduced in a generation of papers — turned worm spread from anecdote into measurement. The patch had been available for twenty-nine days.


376 bytes

UDP 1434 — 2003

No message, no files, no payload — just 376 bytes moving at the speed of bandwidth. The fastest outbreak ever measured, told in its own numbers.

size:            376 bytes -- one UDP packet
port:            1434 (SQL Server Resolution Service)
released:        25 January 2003, ~05:30 UTC
doubling time:   ~8.5 seconds
saturation:      >90% of vulnerable hosts in ~10 minutes
victims:         ~75,000 hosts
message:         none
files written:   none
patch available: July 2002, six months earlier

At half past five in the morning UTC on 25 January 2003, a single malformed UDP packet began arriving at database servers. Any unpatched Microsoft SQL Server that received it was, in that instant, transmitting the same packet to random addresses as fast as its network link allowed. There was nothing else: no file written, no message shown, no instruction awaited.

The numbers opposite are the artifact, measured by researchers who reconstructed the outbreak from monitoring data: infections doubling every eight and a half seconds, ninety percent of vulnerable hosts taken within ten minutes. Connectionless UDP made the worm bandwidth-limited — it spread as fast as wires could carry it, an order of magnitude beyond anything before. The patch had existed for six months.

The collateral damage was pure congestion: bank machines declined withdrawals, flights were delayed, an emergency call center fell back to paper, and much of South Korea lost connectivity — harm done by traffic alone, authored by no payload. Slammer ended the assumption that humans could react to an outbreak in time, and the automated-defense literature dates from its ten minutes.


billy gates why do you make this possible ?

WIN32 / RPC — 2003

Inside the binary that rebooted the world's desktops, two messages waited for the analysts: one of love, one addressed to the richest man alive.

msblast.exe

I just want to say LOVE YOU SAN!!

billy gates why do you make this possible ? Stop
making money and fix your software!!

--

flood target: windowsupdate.com, from 16 August 2003

Blaster arrived on 11 August 2003 through a hole in the Windows RPC service, patched four weeks earlier. Its victims experienced it as a countdown dialog and a reboot loop — millions of home computers restarting over and over, the first worm many ordinary users ever watched interrupt their own screens. Analysts who opened the executable found the two strings shown opposite compiled into it, a valentine and a complaint.

The worm's plan had a target: from 16 August, every infected machine would flood windowsupdate.com, the address victims would use to fetch the cure. Microsoft's countermeasure was almost comic — the name was only a redirect, so the company deleted it from DNS and the flood fell on nothing. Days later a vigilante worm, Welchia, spread through the same hole to install the patch, and made the congestion worse.

An eighteen-year-old who modified and re-released the B variant went to federal prison; the original author was never found — an asymmetry that became a pattern in malware justice. The taunt aimed at Bill Gates outlived the outbreak: quoted in every retrospective, it fixed the era's frustration with patch-speed security into thirteen words of lowercase reproach.


50,000 domains a day

WIN32 / DNS — 2008

The worm that said nothing and held millions: a botnet kept headless only by pre-registering fifty thousand domain names a day.

also known as:    Downadup, Kido
entry:            MS08-067, patched 23 October 2008
first identified: 21 November 2008

rendezvous, variant A:  250 pseudorandom domains/day
rendezvous, variant C:  50,000 candidates/day

on infection:  blocks lookups of security vendors
               disables update and security services
               spreads by USB autorun and weak
               admin passwords

reward posted: USD 250,000 (Microsoft, 12 Feb 2009)
payload fired: none

Conficker showed its victims no message at all. Arriving through a Windows service hole patched in a rare emergency release weeks before, it settled in quietly, blocked visits to security vendors, disabled updates, and each day computed a fresh list of rendezvous domains where instructions might appear. Defenders who reversed the algorithm could register tomorrow's names first — so the third variant raised the daily list to fifty thousand.

The response invented a new unit of defense: not the firewall but the namespace. Microsoft, ICANN, registrars, and researchers — the Conficker Working Group — coordinated across more than a hundred top-level domains to deny the botnet its meeting points, while a quarter-million-dollar bounty stood for the authors' names. The press fixed on 1 April 2009, when a new algorithm would activate; the day passed in silence.

Estimates at the peak ran to many millions of machines, and then — anticlimax. The botnet's only observed commerce was a brief spam-and-scareware delivery before that variant deleted itself. No payload ever fired; the bounty was never claimed; infected machines pulsed for years in forgotten corners. Conficker remains the field's great unfinished sentence: capability assembled at continental scale, purpose never stated.


Ooops, your files have been encrypted!

SMB / RANSOMWARE — 2017

A stolen intelligence exploit, a ransom note in broken English, and hospitals diverting ambulances by mid-afternoon: the day worms came back.

Ooops, your files have been encrypted!

What Happened to My Computer?
  Your important files are encrypted.

Can I Recover My Files?
  Sure. We guarantee that you can recover all
  your files safely and easily. But you have
  not so enough time.

Send $300 worth of bitcoin to this address:

                       [addresses withheld]

@WanaDecryptor@.exe

On the morning of 12 May 2017, screens in British hospitals, Spanish telecoms, German rail stations, and factories on four continents turned to the note opposite. WannaCry crossed networks by itself — the first great worm in years — using an exploit developed by the US National Security Agency, stolen and published a month earlier, against a Windows flaw patched two months before that.

The countdown interface demanded three hundred dollars in bitcoin, doubling after three days. That afternoon a British researcher, Marcus Hutchins, noticed the code queried an unregistered domain and registered it; the worm read the answer as a stop signal, and the spread collapsed as abruptly as it had begun. Europol counted some two hundred thousand machines across a hundred and fifty countries. The UK health service, running unsupported systems, cancelled appointments for days.

The United States later charged a North Korean operator, placing the outbreak inside a state program and completing the arc that began with a laboratory taunt on one network: the worm as an instrument of geopolitics, priced in cryptocurrency. Every argument WannaCry started — about hoarded exploits, unsupported software, and hospitals downstream of both — is still going.


Full provenance for every piece is maintained in the SOURCE MATERIAL archive, one canonical record per artifact. Editorial safety line for no. 002: the specimens printed in this collection are exclusively non-functional, human-facing artifacts — messages, banners, ransom text, filenames, and measured statistics. No functional exploit, propagation, or payload code is reproduced, in any framing, as a deliberate editorial policy of the series.

SOURCE MATERIAL is a recurring series about historically significant code and the systems it ran on. Each piece is fact-checked against primary sources where they survive; reproduction status (verbatim, abridged, reconstructed, compiled) is declared per artifact, and corrections are recorded in a versioned archive.

A note on what is not here: this number is about self-replicating programs, and not one line of self-replicating program appears in it. Every panel holds what the worms showed people — their messages, banners, ransom notes, filenames, and measured numbers — never the code that spread them. That is a hard editorial line of the series, not a limitation of research.

Set in Helvetica and DejaVu Sans Mono on US Letter. Body pages follow the series plate: title band, deck, specimen panel, three untitled prose blocks, and a footer of fragments. The palette is cream, ink, and one accent per issue; no. 002 wears phosphor green.

curated, written, compiled, and typeset by Steven Delpercio · delpercio.dev