Trojan

About “Trojan:Win32/WhisperGate.ES!MTB” infection

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: 3E579E09191F95015638.mlw
path: /opt/CAPEv2/storage/binaries/bc4f21de09388cc9642bd8f44be21f035954656ecf0d4a9448cf4fe158d9ff5f
crc32: 4D4F3D73
md5: 3e579e09191f95015638d5ff7271931a
sha1: a096c3cacb8f13f691074a8f6e6829f42fac51f9
sha256: bc4f21de09388cc9642bd8f44be21f035954656ecf0d4a9448cf4fe158d9ff5f
sha512: bf46941357f5dbe6365d29e4022ee3f223a7747c7eda844b1dcd8189b09a58e7b77aed059c808ff93c606e8583fa16606e921c3589fa5b2b3d91eac4883fa207
ssdeep: 768:xkfREp3lRcqpZG7ESagBjPP3lLuzZPKqn1FsEuoxG8h8aEsgLRm:xkQl/G7EuJPP3lLuBZn1FzuoI8h8aEsT
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12223F855BE698CEBE652633E80EBC377577CF1818B230B53BB24BB341B537922494246
sha3_384: 21528c497b1e9c4d036ffdb42b0c2ac344d0c791a4fac7d1087f9077bf50fced813d203b474d48c7b8466f08502817cd
ep_bytes: 83ec1cc7042401000000ff154c924000
timestamp: 2023-12-22 09:53:41

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.531666
ClamAVWin.Trojan.Generic-10017566-0
MalwarebytesTrojan.Injector
VIPREGen:Variant.Zusy.531666
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005b00591 )
K7GWTrojan ( 005b00591 )
Cybereasonmalicious.acb8f1
ArcabitTrojan.Zusy.D81CD2
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@aGZkWPg
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Sdum.gen
BitDefenderGen:Variant.Zusy.531666
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Zusy.531666 (B)
DrWebBACKDOOR.Trojan
IkarusTrojan.Win32.Agent
JiangminTrojan.Generic.bjgvg
GoogleDetected
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
ZoneAlarmVHO:Trojan.Win32.Sdum.gen
GDataWin32.Trojan.PSE.119QQ95
VaristW32/Kryptik.LIO.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R630433
MAXmalware (ai score=89)
Cylanceunsafe
RisingTrojan.Agent!8.B1E (TFE:5:eTucSJaHBhU)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment