It tried to spread itself by looking for more IIS servers on the Internet.
It waited 20-27 days after it was installed to launch denial of service attacks to the several fixed IP addresses. The IP address of the White House web server was among those.