Mirai - Detection Rate

VirusTotal detection statistics across 119 analyzed samples.

Last updated: 2026-05-11

Detection rates show how many antivirus engines on VirusTotal identify Mirai samples as malicious. A high detection rate (30+ engines) means most AV vendors have signatures for the variant. Low or zero detection indicates recently packed or obfuscated samples that may bypass signature-based endpoint protection.

Why Detection Rate Matters

For SOC analysts and threat hunters, detection rate is a key indicator of variant freshness and evasion capability. When Mirai operators release a new build with updated packing or obfuscation, detection rates drop temporarily until AV vendors update their signatures. This window of low detection is when organizations are most vulnerable. Monitoring this page helps you understand how well your current defenses cover Mirai variants.

Recommended Actions

If you see undetected or low-detection samples, consider submitting them to your sandbox for behavioral analysis. Update your YARA rules to catch Mirai patterns that signature-based detection misses. For the latest sample hashes to cross-reference, visit the Mirai samples page. For network-level indicators, check the IOC page.

26/62
Avg Detection
119
Samples Analyzed
56
High Detection
0
Undetected

Detection Distribution

High (30+) 56 (47%)
Medium (15-29) 32 (27%)
Low (1-14) 31 (26%)
Undetected (0) 0 (0%)

Per-Sample Detection

SHA256 Detection Threat Name
5448763c8ac93e6b... 46/64 trojan.mirai/gafgyt
788cd17336cd3fd0... 45/65 trojan.mirai/ddos
51a5da3ff8e7a94b... 45/64 trojan.mirai/gafgyt
76cddb38dba8d8b7... 44/65 trojan.mirai/bonb
09e0f144fc215441... 44/65 trojan.mirai/bonb
2f594939c4eba15b... 44/65 trojan.mirai/bonb
95867262e5a88b7f... 44/64 trojan.mirai/gafgyt
17b895fcfb6dc7a8... 44/64 trojan.mirai/gafgyt
bb1f21fc18f8c0df... 42/62 trojan.mirai/ddos
2d42e16b1759e6b6... 42/61 trojan.mirai/ddos
6a1ce24ec7f4253f... 42/61 trojan.mirai/gafgyt
03613a1db3c53c99... 42/64 trojan.mirai/gafgyt
21f3912c547f6797... 41/60 trojan.mirai/gafgyt
aa4d2cdb81d2d32f... 41/60 trojan.mirai/gafgyt
5e44e14fc012b3b5... 41/64 trojan.mirai/ddos
a00fad2ab3de4c73... 41/64 trojan.mirai/ddos
5f6b8752c7d16bd6... 41/64 trojan.mirai/ddos
8944c1c38f79ceda... 39/61 trojan.mirai/bonb
6764b46bf6bceb4c... 39/61 trojan.mirai/bonb
aaecb33a35395673... 39/57 trojan.mirai/gafgyt
d4aecb083f660af8... 39/57 trojan.mirai/ddos
27d397f799ed511d... 39/64 trojan.mirai/bootnet
bb5cef7936de6236... 39/65 trojan.mirai/ddos
be7193c29d39c171... 39/62 trojan.mirai/ddos
0987991d86065571... 39/62 trojan.mirai/ddos
5e2f8f4983d9ace0... 38/57 trojan.mirai/bonb
b684714154f55c58... 38/64 trojan.mirai/genericrxtl
63e476ac8c537dcf... 38/65 trojan.mirai/ddos
71e6413ff026ba54... 38/63 trojan.mirai/gafgyt
a49d0f67c34bd65b... 38/64 trojan.mirai/ddos
036f40658e50de29... 38/63 trojan.mirai/ddos
f94f28a7594e854a... 38/62 trojan.mirai/ddos
3724c804231366ed... 37/65 trojan.mirai/gafgyt
64ae5db068e064c0... 37/56 trojan.mirai/ddos
59efbdbbfa5a6c65... 37/62 trojan.mirai/ddos
10f5d4ee9aba8d77... 37/64 trojan.mirai/gafgyt
51ca545ea4c1b659... 36/65 trojan.mirai/ddos
df94e452c3115889... 36/62 trojan.mirai/ddos
faebd5ba34e23efb... 36/63 trojan.mirai/gafgyt
5fc52953f79ce69b... 36/59 downloader.medusa/shell
2ea0d31c3c95a87e... 35/65 trojan.mirai/gafgyt
bef1502fc32fd7b6... 35/63 trojan.mirai/possible
26c923ffa4f40b3f... 34/58 trojan.mirai/ddos
dc0853f8854f97de... 34/57 trojan.mirai/r002c0cdl26
d73b18d4b3d801e2... 33/64 trojan.mirai/gafgyt
e6ab66d6f9f19908... 33/64 trojan.mirai/gafgyt
00044a61791fdb2f... 33/62 trojan.mirai/r002c0de326
6ebf284fa478eea9... 33/63 trojan.mirai/gafgyt
2f933ed96fab4c6f... 32/58 trojan.mirai/r002c0cdl26
d7e4cadc5fea4e79... 32/65 trojan.mirai/expl