Trojan

What is “Trojan:Win32/WhisperGate.ES!MTB”?

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: 16F9744D792826B09557.mlw
path: /opt/CAPEv2/storage/binaries/66fee27e4102dd197a801e336d3a412218a41eaf70c8deca53454c1e6b4c710c
crc32: 671E30EB
md5: 16f9744d792826b0955707242c28a224
sha1: 8e61404f34ed71f33827641b0aa7b25fe73ee70e
sha256: 66fee27e4102dd197a801e336d3a412218a41eaf70c8deca53454c1e6b4c710c
sha512: 8564796dea711d2c11dd9d01e32136a209217b15e4d89501e7d345319e0e8bac962826b73e5f9a55e553d7ea909bf96e39f1ae4777116129c99356f56f1e043d
ssdeep: 768:p0XPVYJEMp4MiniDsZE4Z8PP3lLuzZPKqgOGQB/vs6uuPxo8czgdRm:O944BiDsDCPP3lLuBZgOGQB/vs6uuPad
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B823F855BE658CEBE651633E80EBC77B5B3DF5818B231B53BB34BB345B032922094246
sha3_384: 57ae618ee0ffd83f2662efede819cee2044d7542523b8427e1a5c4a4075f5f1c2dee10f6fdefc6bee40f8a7495756760
ep_bytes: 83ec1cc7042401000000ff151c924000
timestamp: 2023-12-22 10:15:04

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
MalwarebytesTrojan.Injector
VIPREGen:Variant.Zusy.531379
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005b00591 )
K7GWTrojan ( 005b00591 )
CrowdStrikewin/malicious_confidence_70% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CZP
ClamAVWin.Trojan.Generic-10017566-0
BitDefenderGen:Variant.Zusy.531379
MicroWorld-eScanGen:Variant.Zusy.531379
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Zusy.531379 (B)
DrWebBACKDOOR.Trojan
SophosTroj/Inject-JGZ
GDataWin32.Trojan.PSE.119QQ95
JiangminTrojan.Generic.bjgvg
GoogleDetected
Kingsoftmalware.kb.a.737
ArcabitTrojan.Zusy.D81BB3
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
VaristW32/Kryptik.LIO.gen!Eldorado
AhnLab-V3Malware/Win.Generic.R629739
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@a8Dy7zm
MAXmalware (ai score=82)
Cylanceunsafe
RisingTrojan.Agent!8.B1E (TFE:5:7V0DE5QEnfF)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.f34ed7
DeepInstinctMALICIOUS

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment