Trojan

What is “Trojan:Win32/WhisperGate.ES!MTB”?

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: C74B8E95189714C20CE0.mlw
path: /opt/CAPEv2/storage/binaries/6535728bbacd69881ff7f71ed12e278453570b9b90894c34d0f6b987f0bfb6b4
crc32: 1D9784F5
md5: c74b8e95189714c20ce08485917a8998
sha1: dd033ba10e26f559bc727379d1a93253d2c23e30
sha256: 6535728bbacd69881ff7f71ed12e278453570b9b90894c34d0f6b987f0bfb6b4
sha512: 1328686f2e4210b1369f76423e0d66e24ee6213cc45d2956c6a16d8426fd118c948aa08f85a3b6d2520d461494348e9cadbc1c37da1399ebfe2cdf32628ff0f5
ssdeep: 768:O8gBEpHVFVp03I4XbmEgBsPP3lLuzZPKq313ETuAMTPpfDyx2h84sgdRm:O8zV3aIE82PP3lLuBZ313vTPRDyQh84a
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16E230855BA658CEBE651633E80EBC37B5B7DF1818B230B53BB30BB305B533922095646
sha3_384: 6a54e068d14591e457b191867d1649de18a7ced20e2eb744f3c5794333dd4a6ea363fcbaa97f51cff3a7a728ec60fa7b
ep_bytes: 83ec1cc7042401000000ff153c924000
timestamp: 2023-12-22 09:50:40

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.531666
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005b00591 )
K7GWTrojan ( 005b00591 )
Cybereasonmalicious.10e26f
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
ClamAVWin.Trojan.Generic-10017566-0
KasperskyVHO:Trojan.Win32.Convagent.gen
BitDefenderGen:Variant.Zusy.531666
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Zusy.531666 (B)
DrWebBACKDOOR.Trojan
VIPREGen:Variant.Zusy.531666
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.119QQ95
JiangminTrojan.Generic.bjgvg
VaristW32/Kryptik.LIO.gen!Eldorado
ArcabitTrojan.Zusy.D81CD2
ZoneAlarmVHO:Trojan.Win32.Convagent.gen
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R630433
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@aG!kAnp
MAXmalware (ai score=85)
MalwarebytesTrojan.Injector
RisingTrojan.Agent!8.B1E (TFE:5:n8ps0hqdrvP)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment