SIGRUN-RANSOMWARE
SIGRUN-RANSOMWARESigrun Ransomware
Description
When Sigrun is executed it will first check "HKEY_CURRENT_USER\Keyboard Layout\Preload" to see if it is set to the Russian layout. If the computer is using a Russian layout, it will not encrypt the computer and just delete itself. Otherwise Sigrun will scan a computer for files to encrypt and skip any that match certain extensions, filenames, or are located in particular folders.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.