Each infected machine checks around 600 IP addresses every hour in an attempt to find other infected machines which have more recent code and update itself. The probability for an infected machine to find the single existing updated machine, in the first try, is 1 in three billion. Using this system, the entire network could be updated in just 16 hours per hour. P2P update system is less visible, with only requirement is to introduce new machine (or several hundred) which are already updated and accessible from anywhere.”]
Source: https://www.bitdefender.com/blog/hotforsecurity/conficker-april-surprise/

