| Threat Alias | Number of Incidents |
| Backdoor.IRCBot [PC Tools] | 244 |
| Backdoor.Trojan [Symantec] | 210 |
| Backdoor:Win32/Kirsun.A [Microsoft] | 165 |
| Troj/Kirsun-A [Sophos] | 165 |
| Win-Trojan/Kirsun.652800 [AhnLab] | 120 |
| BKDR_KIRSUN.A [Trend Micro] | 90 |
| not-a-virus:Client-IRC.Win32.mIRC [Ikarus] | 63 |
| IRC.Backdoor.Trojan [Symantec] | 52 |
| BKDR_FLOOD.BC [Trend Micro] | 6 |
| TROJ_KIRSUN.A [Trend Micro] | 4 |
| Backdoor:Win32/IRCbot [Microsoft] | 3 |
| Generic PUP.x [McAfee] | 3 |
| Mal/Generic-A [Sophos] | 3 |
| not-a-virus:RiskTool.Win32.HideWindows [Kaspersky Lab] | 3 |
| Backdoor.mIRC-based.P [PC Tools] | 2 |
| not-a-virus:NetTool.Win32.Sniffer.c [Kaspersky Lab] | 2 |
| Trojan.DR.Duckirc.Gen [PC Tools] | 2 |
| Adware.2Search [Symantec] | 1 |
| Application.Ardamax_Keylogger [PC Tools] | 1 |
| Backdoor.IRC.Zapchast [Ikarus] | 1 |
| BKDR_FLOOD.B [Trend Micro] | 1 |
| Dropper/Malware.904117 [AhnLab] | 1 |
| Generic BackDoor [McAfee] | 1 |
| Generic BackDoor!bf [McAfee] | 1 |
| Hacktool.Flooder [Symantec] | 1 |
| IRC/Flood.mirc [McAfee] | 1 |
| not-a-virus:PSWTool.Win32.PassView.162 [Kaspersky Lab] | 1 |
| not-a-virus:RiskTool.Win32.HideWindows [Ikarus] | 1 |
| W32/Spybot.worm!bm [McAfee] | 1 |
| Win-Trojan/Xema.variant [AhnLab] | 1 |