Trojan

Trojan:Win32/WhisperGate.RA!MTB information

Malware Removal

The Trojan:Win32/WhisperGate.RA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.RA!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.RA!MTB?


File Info:

name: 2D82CB52970BF4BD0052.mlw
path: /opt/CAPEv2/storage/binaries/e5558b164b690b6ac8441c4c534e729e01bd46b95bbc673d355580fc2ce6b60d
crc32: C0007534
md5: 2d82cb52970bf4bd0052fbe3c62a6e09
sha1: af1d71e4cf00864a917f9c6d8b8537056ecd4cb2
sha256: e5558b164b690b6ac8441c4c534e729e01bd46b95bbc673d355580fc2ce6b60d
sha512: cb8d6ed42a4423ab422ceaa18ac1e93ab2cb0a19a8628205ee8d9ab66ed917e52ec24aa7997a7c22646c05634d08e74862815910801697428719f2e269983023
ssdeep: 768:P7pEW2vK90qxYeSa19WPP3lLuzZPKqKMcU9mpTq2G9bmhxgcRE:POSLOebkPP3lLuBZKHugTqP9bmhxq
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1FE231995BE658CEBE681633E84EBC377977DF1808B230B53B734B6346B437922094246
sha3_384: a8ba0be37c5a96860947013d3502f71ff7f424c8408f2ee861d72f8dc7947706e2dde75a4977ec36bedc77195bcf754f
ep_bytes: 83ec1cc7042401000000ff156c924000
timestamp: 2023-12-21 13:30:27

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.RA!MTB also known as:

BkavW32.Common.31A70263
LionicTrojan.Win32.Dacic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Dacic.1206.7F2F4FB2
ClamAVWin.Trojan.Generic-10017566-0
FireEyeGeneric.mg.2d82cb52970bf4bd
SkyhighBehavesLike.Win32.Generic.pm
ALYacGeneric.Dacic.1206.7F2F4FB2
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005b11261 )
AlibabaTrojan:Win32/WhisperGate.bee7fa4c
K7GWTrojan ( 005b11261 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36744.d0Y@amEkLnd
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Shellex.gen
BitDefenderGeneric.Dacic.1206.7F2F4FB2
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Shellex.ka
EmsisoftGeneric.Dacic.1206.7F2F4FB2 (B)
F-SecureTrojan.TR/Agent_AGen.tfdlm
VIPREGeneric.Dacic.1206.7F2F4FB2
TrendMicroTROJ_GEN.R002C0DAK24
SophosTroj/Inject-JGZ
IkarusTrojan.Win32.Agent
GDataWin32.Trojan.PSE.1C23UVS
JiangminTrojan.Generic.bjgvg
GoogleDetected
AviraTR/Agent_AGen.tfdlm
Antiy-AVLTrojan/Win32.WhisperGate
ArcabitGeneric.Dacic.1206.7F2F4FB2
ZoneAlarmHEUR:Trojan.Win32.Shellex.gen
MicrosoftTrojan:Win32/WhisperGate.RA!MTB
VaristW32/Kryptik.LIO.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R630086
McAfeeArtemis!2D82CB52970B
MAXmalware (ai score=82)
MalwarebytesTrojan.Injector
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DAK24
RisingTrojan.Agent!8.B1E (TFE:5:hRAzomecsOP)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/WhisperGate.RA!MTB?

Trojan:Win32/WhisperGate.RA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment