Trojan

Trojan:Win32/WhisperGate.ES!MTB malicious file

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: A11DC594BE6DFE70F85E.mlw
path: /opt/CAPEv2/storage/binaries/cd35be47f5155c16d34632888367bb75a89caad60a20092a00a626ed35e86c78
crc32: 501A15BF
md5: a11dc594be6dfe70f85ee4f31c9eb75b
sha1: 34eb8026938b04bc3617c216d8cbd5993db89519
sha256: cd35be47f5155c16d34632888367bb75a89caad60a20092a00a626ed35e86c78
sha512: b89cf6c5cb6f0e660226799ab63ce659fa083a2720fba31cff4da1b2e3ab0b4f0644458e2e04ebd86516704fd47101b4da37ac6cdf9ff28beb351ab8da844bbc
ssdeep: 768:T7REUuY6qTFQJQgEZEzRgPP3lLuzZPKqn8wqmqUoAcdtxo85zgkRm:gY9kYUWPP3lLuBZn8cqUoAcdta85z+
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C4230855BE648CEBE651633E80EBC77B5B7DF5818B230B53BB34BB341B132922094246
sha3_384: 49ea881e17cbd11a3f84940e340618137da5a95fc379a598a73355b4fdf7ea6264cd8554048a1f8fe9aa118197fae5d4
ep_bytes: 83ec1cc7042401000000ff1524924000
timestamp: 2023-12-22 07:19:41

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zusy.4!c
MicroWorld-eScanGen:Variant.Zusy.531381
FireEyeGeneric.mg.a11dc594be6dfe70
SkyhighBehavesLike.Win32.Injector.pm
McAfeeArtemis!A11DC594BE6D
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005afe0e1 )
AlibabaTrojan:Win32/Generic.64deaf4a
K7GWTrojan ( 005afe0e1 )
ArcabitTrojan.Zusy.D81BB5
BitDefenderThetaGen:NN.ZexaF.36608.c0Y@ae5Bm9o
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
ClamAVWin.Trojan.Generic-10017566-0
BitDefenderGen:Variant.Zusy.531381
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Zusy.531381 (B)
F-SecureTrojan.TR/Agent_AGen.ytevc
VIPREGen:Variant.Zusy.531381
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
JiangminTrojan.Generic.bjgvg
VaristW32/Kryptik.LIO.gen!Eldorado
AviraTR/Agent_AGen.ytevc
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
ViRobotTrojan.Win.Z.Zusy.47152.K
GDataWin32.Trojan.PSE.SMV3QT
GoogleDetected
AhnLab-V3Malware/Win.Generic.R629734
ALYacGen:Variant.Zusy.531381
MAXmalware (ai score=80)
MalwarebytesTrojan.Injector
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H09LV23
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment