Trojan

Trojan:Win32/WhisperGate.ES!MTB information

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: 72A5650D41397FE6C1E5.mlw
path: /opt/CAPEv2/storage/binaries/727980171f7fe02af607e14f0301b864564ea5bf433ed958ebbe9f76883bfb28
crc32: C0CB6A3B
md5: 72a5650d41397fe6c1e5e97e4143efca
sha1: 2751657f995f749141e6e5b80db8f01c4b6732bc
sha256: 727980171f7fe02af607e14f0301b864564ea5bf433ed958ebbe9f76883bfb28
sha512: b9dcc9d988682283ecac0ff06eaedd0a0db2d2639decdd1ce33385b8eb044b8ccdb40ee1f24bba13fe6e5c4bdc961ad5c937cb1fb589517ad6b73718756757c6
ssdeep: 768:Tj4BxlEl5B6qEpTDKbTZEX1bPP3lLuzZPKqDMIkd1GTz+sxGhbbgkR5:TEeBKFDiTwZPP3lLuBZDMRiz+sUhbbR
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T116230855BA658CEBE652633E80EBC37B577DF1818B231B53BB34BB305B133922094646
sha3_384: f47eb5d775905b10b05bac29fb352e5bc4478d3e8c2751b96e9741d839326cdec997ab8adc87cc63cd1fdc7ed520c659
ep_bytes: 83ec1cc7042401000000ff1530924000
timestamp: 2023-12-22 08:52:19

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Dacic.1206.37496086
FireEyeGeneric.mg.72a5650d41397fe6
SkyhighBehavesLike.Win32.Generic.pm
McAfeeArtemis!72A5650D4139
Cylanceunsafe
VIPREGeneric.Dacic.1206.37496086
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005b11261 )
AlibabaTrojan:Win32/WhisperGate.93235bf0
K7GWTrojan ( 005b11261 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitGeneric.Dacic.1206.37496086
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@a0FcFde
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CZP
ClamAVWin.Trojan.Generic-10017566-0
KasperskyHEUR:Trojan.Win32.Shellex.gen
BitDefenderGeneric.Dacic.1206.37496086
AvastWin32:MalwareX-gen [Trj]
TencentTrojan.Win32.Agent.hel
EmsisoftGeneric.Dacic.1206.37496086 (B)
TrendMicroTROJ_GEN.R002C0DA924
SophosTroj/Inject-JGZ
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.bjgvg
GoogleDetected
VaristW32/Kryptik.LIO.gen!Eldorado
Antiy-AVLTrojan/Win32.WhisperGate
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
ZoneAlarmHEUR:Trojan.Win32.Shellex.gen
GDataWin32.Trojan.PSE.11FY7F6
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R630324
VBA32Trojan.Shellex
ALYacGeneric.Dacic.1206.37496086
MAXmalware (ai score=88)
MalwarebytesTrojan.Injector
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DA924
RisingTrojan.Agent!8.B1E (TFE:5:kyIXDqGSu3K)
IkarusTrojan.Win32.Agent
FortinetW32/Agent.CZK!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment