Trojan

Trojan:Win32/WhisperGate.ES!MTB information

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: 27C9AB4DF08B87757E52.mlw
path: /opt/CAPEv2/storage/binaries/a69bfb380e25e00a61ffc30b658bc44396360b943475f620b25bfcac78a3aaed
crc32: 76EF8A92
md5: 27c9ab4df08b87757e52484a8be0c0e2
sha1: fe9b906f72ce7a6a666373844b8b235dec8cd511
sha256: a69bfb380e25e00a61ffc30b658bc44396360b943475f620b25bfcac78a3aaed
sha512: 56a90f3cf4e426abb6e994878f18ae157530a739363f8101910328ffdcbf0cbc77e02b60854f81d1dbbfa3f5ae68cf07ffd9815ae516e217bc849638b884394a
ssdeep: 768:+V4ylES2Ee5DuVJQ8cISaYRiPP3lLuzZPKqOoBr9De2G9YrktgLRE:+V4LEfm8cImcPP3lLuBZOo99DeP9Yrk7
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16C230A55BE658CEBE691633E84EBC37B577CF5808B230B53B734BA306B537922094246
sha3_384: 40eeabd3e9bc1c7accac17a2d399c0d9692eb65c0ad97c4b9a59de3c5517a047b3f25485dd35f9cf353ee4586f68672a
ep_bytes: 83ec1cc7042401000000ff1560924000
timestamp: 2023-12-22 11:13:32

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.AIDetectMalware
DrWebBACKDOOR.Trojan
MicroWorld-eScanGen:Variant.Zusy.531614
ClamAVWin.Trojan.Generic-10017566-0
MalwarebytesTrojan.Injector
VIPREGen:Variant.Zusy.531614
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005b00591 )
K7GWTrojan ( 005b00591 )
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitTrojan.Zusy.D81C9E
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@aC3lXEl
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.531614
AvastWin32:Evo-gen [Trj]
RisingTrojan.Agent!8.B1E (TFE:5:uxQab1l21ZR)
EmsisoftGen:Variant.Zusy.531614 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.bjgvg
GoogleDetected
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
GDataWin32.Trojan.PSE.CRM4WV
VaristW32/Kryptik.LIO.gen!Eldorado
AhnLab-V3Malware/Win.Generic.R629739
Cylanceunsafe
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.f72ce7
DeepInstinctMALICIOUS

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment