Trojan

About “Trojan:Win32/WhisperGate.ES!MTB” infection

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: FE82887E142026630671.mlw
path: /opt/CAPEv2/storage/binaries/9ca77cd7fdc01159a48ae020bc72c28c41a1edff8e2afe5e9c6f662332d34375
crc32: 66DD270C
md5: fe82887e142026630671ab718d64ad14
sha1: 71902844736f8d4ee2eee87e60b3ccb5ed0c442d
sha256: 9ca77cd7fdc01159a48ae020bc72c28c41a1edff8e2afe5e9c6f662332d34375
sha512: ea013c59b019c65f9af8ad00fe0960f92c94940123ec27075a8917f5338f9ebdd534a0fc30c89657c0d35266d2da58824f87b4e54e9fe3ab4eefc224ad4ba3d7
ssdeep: 768:cXZj/xEhzoCS4F2QtZEP9nPP3lLuzZPKqnzN9l5lAMb8xGhSQgkR5:cXZjUoKvto1PP3lLuBZnzN9DlAMb8Uhx
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19E231995BE658CEBE651633E80EBC37B5B7DF5818B230B93B734FA341B132912494246
sha3_384: 6d3fa30abf86219c347753d0de31a38c5ddeb7e7990d8c2c2736a6bf0bb991f60e370d8539392f931f6b34095db99fa4
ep_bytes: 83ec1cc7042401000000ff1534924000
timestamp: 2023-12-22 08:30:48

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Zusy.531372
FireEyeGeneric.mg.fe82887e14202663
SkyhighBehavesLike.Win32.Injector.pm
ALYacGen:Variant.Zusy.531372
MalwarebytesTrojan.Injector
SangforSuspicious.Win32.Save.a
AlibabaTrojan:Win32/WhisperGate.f5eed69f
ArcabitTrojan.Zusy.D81BAC
BitDefenderThetaGen:NN.ZexaF.36608.c0Y@a0GCrhm
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
ClamAVWin.Trojan.Generic-10017566-0
BitDefenderGen:Variant.Zusy.531372
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Zusy.531372 (B)
VIPREGen:Variant.Zusy.531372
IkarusTrojan.Win32.Agent
JiangminTrojan.Generic.bjgvg
VaristW32/Kryptik.LIO.gen!Eldorado
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
GDataWin32.Trojan.PSE.1S14ZGS
GoogleDetected
AhnLab-V3Malware/Win.Generic.R629736
McAfeeArtemis!FE82887E1420
MAXmalware (ai score=86)
Cylanceunsafe
RisingTrojan.Agent!8.B1E (TFE:5:lX7C7DaYhHE)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment