- Distribution Method : Unknown
- MD5 : 71a10f759c8030ffcfbb136cb38823a3
- Major Detection Name : Gen:Heur.Ransom.HiddenTears.1 (BitDefender), Ransom-Saramat!71A10F759C80 (McAfee)
- Encrypted File Pattern : .Saramat
- Malicious File Creation Location : <Drive Letter>:\Attention!.Exe
- Payment Instrucition File : Decrypt.txt
- Major Characteristics :
- Offline Encryption
- Hidden-Tear open source based ransomware
- Duplicate ransomware executables in root path of each drive to induce its execution.
List