Trojan

What is “Trojan:Win32/WhisperGate.ES!MTB”?

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: 0F182DD9E412441DFFFF.mlw
path: /opt/CAPEv2/storage/binaries/26de3287ea97a8b3f10d9961a497b3d9526630449165f88b6066bc8320766f80
crc32: B586A8DA
md5: 0f182dd9e412441dffff294e06542263
sha1: ae5be4350811d74294ab287f203ed0a5d08dfdf2
sha256: 26de3287ea97a8b3f10d9961a497b3d9526630449165f88b6066bc8320766f80
sha512: 615281e12638b4793913d9e1829030d09b3994765d33b8c9a8d927ca655d85a2be2a85634f5af0f7c4a9012dabbfa20f2554be314118c5496ef55c929ac26dc5
ssdeep: 768:3DSOmuxptEA8hB+pmidZE69APP3lLuzZPKqQ7OgDHhHoNixGhfbgdR5:3DSOr6hA9dByPP3lLuBZQ7RDBH6iUhfm
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17F230855BE658CEBE652633E80EBC37B5B7DF5818B231B53B734BB305B132922094246
sha3_384: f47f5f44b9497c5d09f312be7ebbe363a0efc7b4ceb3406ff05f3dc0a726a6da1047c7d03ee848be33b1f0dc16810c84
ep_bytes: 83ec1cc7042401000000ff1528924000
timestamp: 2023-12-22 09:24:38

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Zusy.531604
ClamAVWin.Trojan.Generic-10017566-0
FireEyeGeneric.mg.0f182dd9e412441d
SkyhighBehavesLike.Win32.Generic.pm
McAfeeArtemis!0F182DD9E412
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005b00591 )
AlibabaTrojan:Win32/WhisperGate.0960ad50
K7GWTrojan ( 005b00591 )
Cybereasonmalicious.50811d
ArcabitTrojan.Zusy.D81C94
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.531604
AvastFileRepMalware [Misc]
EmsisoftGen:Variant.Zusy.531604 (B)
VIPREGen:Variant.Zusy.531604
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.bjgvg
GoogleDetected
Kingsoftmalware.kb.a.983
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
GDataWin32.Trojan.PSE.1B885XN
VaristW32/Kryptik.LIO.gen!Eldorado
AhnLab-V3Trojan/Win.TrojanX-gen.R630362
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@aW55cic
MAXmalware (ai score=82)
MalwarebytesTrojan.Injector
RisingTrojan.Agent!8.B1E (TFE:5:daiSIuctnLD)
IkarusTrojan-Downloader.Win32.Small
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment