
A Pastebin Post by a Guest user reads "LizardSquad explosed". The pastebin post contains the research done by an independent researcher who claims to have done extensive research in botnet culture. The person claims that the IRC network used by the LizardSquad is using Linux systems, which are infected with a bot known as Kaiten (detectable as Trojan.Tsunami.B in ClamAV).
The user told that he noticed a flaw in the IRC network of LizardSquad. There were only 290 users on their IRC Channel, but their were 4200 users on the network. When he started a /who, he got flooded with some messages containing Google C&C server names in that messages. After further research the user found that these servers are infected with Kaiten bot. He confirmed this as he got to know some matching characteristics of Kaiten bot in his research work.
Characteristics of Kaiten:
- Kaiten characteristic is that Kaiten generates the USER, IDENT and NICK with makestring
- Kaiten by default sends a MODE-xi (in IRC this would remove hostmasking, allowing you to view the REAL IP of the bots inside of the botnet. usermode -i disables invisible flag (allowing a /who * to show you)
After this the user lists the IPs of Google which have been claimed to be used by LizardSquad for Denial of Servie attacks. Further the paste reads,
"This is an extreme exposure for LizardSquad as we now know this information."
Below are the Screenshots of the paste and Link of the Paste:
http://pastebin.com/655ba54R

Note: Indian ISPs have blocked Pastebin. The above link can be viewed using any proxy website.