Trojan

Trojan:Win32/WhisperGate.ES!MTB (file analysis)

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: 0085EB8A0C2F504B1656.mlw
path: /opt/CAPEv2/storage/binaries/555069b09b10490fbb90e24fb11e776c8ada1b48b2837640238458e32b9cf7da
crc32: EEF98930
md5: 0085eb8a0c2f504b1656af0a02553700
sha1: 018b9b6f706b7cfb073227840673dfe21f63eb47
sha256: 555069b09b10490fbb90e24fb11e776c8ada1b48b2837640238458e32b9cf7da
sha512: 3282412606d097365ccbbfcf7e9c5872504f3141bec7effdc1149d00e3a9fa2d53a98ff7590104acf9c00e94e5520af475c1b00dad3f147cd98f1390d29f1d09
ssdeep: 768:Wi5ELjiypwvzkafSaJl9PP3lLuzZPKqFlpzJ45xGq0OeXsgcR5:WLiLzFfvrPP3lLuBZFvJ45Iq0OeXsP
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16023F955BE658CEBE651633E84E7C37B577CF1818B230B53BB34FA342B536922094246
sha3_384: 7bf29ad151dbfbd4df5f2667f1d2fb228f2354767ab39624c94b6f901cc6d0d6579832a5a3ae87098d6a5da57b73b4da
ep_bytes: 83ec1cc7042401000000ff1574924000
timestamp: 2023-12-21 13:55:52

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

MicroWorld-eScanGeneric.Dacic.1206.66823498
ClamAVWin.Trojan.Generic-10017566-0
MalwarebytesTrojan.Injector
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005b00591 )
K7GWTrojan ( 005b00591 )
ArcabitGeneric.Dacic.1206.66823498
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Shellex.gen
BitDefenderGeneric.Dacic.1206.66823498
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Agent.hel
EmsisoftGeneric.Dacic.1206.66823498 (B)
VIPREGeneric.Dacic.1206.66823498
SophosTroj/Inject-JGZ
IkarusTrojan.Win32.Agent
JiangminTrojan.Generic.bjgvg
GoogleDetected
Antiy-AVLTrojan/Win32.WhisperGate
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
ZoneAlarmHEUR:Trojan.Win32.Shellex.gen
GDataWin32.Trojan.PSE.1C23UVS
VaristW32/Kryptik.LIO.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R630085
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@a8ldQmb
ALYacGeneric.Dacic.1206.66823498
Cylanceunsafe
RisingTrojan.Agent!8.B1E (TFE:5:6Gq9kIgy5ID)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Trojan

Trojan:Win32/WhisperGate.ES!MTB removal

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: 2FC9C0CAF0AC6FCB5CFC.mlw
path: /opt/CAPEv2/storage/binaries/1bac1a9e444d95073874b39e110559b16797838f807399b345f418862f4f8122
crc32: AED44F8C
md5: 2fc9c0caf0ac6fcb5cfc362378ed2a84
sha1: c9a99d22676709df58720a33af3bff759d29f555
sha256: 1bac1a9e444d95073874b39e110559b16797838f807399b345f418862f4f8122
sha512: d1ff210f1fee90211dc9672043512532262b9534ea334a7b7f3fd11908535667051697ecc00382161454b30626cbe4c59ca75e611164fa68822cc8de9ff7cbca
ssdeep: 768:FYJEci4F6bjDZEjZMPP3lLuzZPKqQwD0KIDX4Kxo8czgkRm:h4EvDkyPP3lLuBZQc0KIDX4Ka8cz+
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13723F855BA658CEBE652633E80EBC37B5B7DF1818B231B53B734BB301B132922494246
sha3_384: cbb2b297bfede11eb7bb898ef1843900c3cf18b98cffb13531992531da3b7963d99c8ab4cba72159fd855aa488e49469
ep_bytes: 83ec1cc7042401000000ff151c924000
timestamp: 2023-12-21 13:56:04

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Dacic.1206.1D8F1495
MalwarebytesTrojan.Injector
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005b00591 )
K7GWTrojan ( 005b00591 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
ClamAVWin.Trojan.Generic-10017566-0
KasperskyHEUR:Trojan.Win32.Shellex.gen
BitDefenderGeneric.Dacic.1206.1D8F1495
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Agent.hel
EmsisoftGeneric.Dacic.1206.1D8F1495 (B)
VIPREGeneric.Dacic.1206.1D8F1495
SophosTroj/Inject-JGZ
IkarusTrojan.Win32.Agent
GDataWin32.Trojan.PSE.1B885XN
JiangminTrojan.Generic.bjgvg
VaristW32/Kryptik.LIO.gen!Eldorado
Antiy-AVLTrojan/Win32.WhisperGate
Kingsoftmalware.kb.a.979
ArcabitGeneric.Dacic.1206.1D8F1495
ZoneAlarmHEUR:Trojan.Win32.Shellex.gen
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R630086
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@aKAkXLf
ALYacGeneric.Dacic.1206.1D8F1495
Cylanceunsafe
RisingTrojan.Agent!8.B1E (TFE:5:utdr8wNLVaN)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment