Trojan

Trojan:Win32/WhisperGate.ES!MTB information

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: B3F5F3FA29C404D62CEA.mlw
path: /opt/CAPEv2/storage/binaries/7d0e8645e7d805e7df349c2b93da73cb5efecd456c142257c5a1390d111d9dd3
crc32: AF133E53
md5: b3f5f3fa29c404d62ceaffd0c7be5958
sha1: 2257b9237e3e11c307aff801e0ce646f9777fe47
sha256: 7d0e8645e7d805e7df349c2b93da73cb5efecd456c142257c5a1390d111d9dd3
sha512: a601482aed4b60fe3b0428bb9563d98be908453954bd77f639763a68b997ebcef31cb70daba03de0634b064d8ae32a2eaf3047a744b63de234c30d426927cdbd
ssdeep: 768:xdvpEM3Yl3aSXlmQtakRcPP3lLuzZPKqEjeQJ+ABJCxGgO/2QgLR5:xd5YoKEQJ6PP3lLuBZEjR+ABJCIgO/2f
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A0231A597E658CEBE651633E80EBC37B5B7CF5818B230B53B730BA305B137922494646
sha3_384: eb09f2ed8b5dcfb910f7f5bdde00e1e57b89094f9107e482c4087b91b6d5a31b9538009b1dde1878a81fe4abb591c389
ep_bytes: 83ec1cc7042401000000ff153c924000
timestamp: 2023-12-22 19:47:15

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.Common.06458185
LionicTrojan.Win32.Dacic.4!c
Elasticmalicious (high confidence)
DrWebBACKDOOR.Trojan
MicroWorld-eScanGeneric.Dacic.1206.68E19D3A
FireEyeGeneric.mg.b3f5f3fa29c404d6
SkyhighBehavesLike.Win32.Generic.pm
McAfeeArtemis!B3F5F3FA29C4
MalwarebytesTrojan.Injector
ZillyaTrojan.AgentAGen.Win32.96149
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005b11261 )
AlibabaTrojan:Win32/WhisperGate.6c9233a6
K7GWTrojan ( 005b11261 )
Cybereasonmalicious.a29c40
BitDefenderThetaGen:NN.ZexaF.36802.c0Y@aewk8pb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CZP
TrendMicro-HouseCallTROJ_GEN.R002C0DAK24
ClamAVWin.Trojan.Generic-10017566-0
KasperskyHEUR:Trojan.Win32.Shellex.gen
BitDefenderGeneric.Dacic.1206.68E19D3A
NANO-AntivirusTrojan.Win32.AgentAGen.kimmzi
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Agent.hel
EmsisoftGeneric.Dacic.1206.68E19D3A (B)
F-SecureTrojan.TR/Agent_AGen.uisgd
VIPREGeneric.Dacic.1206.68E19D3A
TrendMicroTROJ_GEN.R002C0DAK24
Trapminesuspicious.low.ml.score
SophosTroj/Inject-JGZ
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=86)
JiangminTrojan.Generic.bjgvg
Webroot
GoogleDetected
AviraTR/Agent_AGen.uisgd
VaristW32/Kryptik.LIO.gen!Eldorado
Antiy-AVLTrojan/Win32.Shellex
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
ArcabitGeneric.Dacic.1206.68E19D3A
ZoneAlarmHEUR:Trojan.Win32.Shellex.gen
GDataWin32.Trojan.PSE.11FY7F6
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.TrojanX-gen.R629788
ALYacGeneric.Dacic.1206.68E19D3A
Cylanceunsafe
PandaTrj/GdSda.A
RisingTrojan.Agent!8.B1E (TFE:5:iPzPAgCSifU)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment