{
	"id": "e1b0496a-b821-4865-b954-a90e76968cb1",
	"created_at": "2026-04-06T00:18:12.831047Z",
	"updated_at": "2026-04-10T03:24:29.604962Z",
	"deleted_at": null,
	"sha1_hash": "bf1ad09784732745682181593bfbbfaf30bde9a3",
	"title": "Snatch (Malware Family)",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 27601,
	"plain_text": "Snatch (Malware Family)\r\nBy Fraunhofer FKIE\r\nArchived: 2026-04-05 19:55:45 UTC\r\nSnatch is a ransomware which infects victims by rebooting the PC into Safe Mode. Most of the existing security\r\nprotections do not run in Safe Mode so that it the malware can act without expected countermeasures and it can\r\nencrypt as many files as it finds. It uses common packers such as UPX to hide its payload.\r\n[TLP:WHITE] win_snatch_auto (20201014 | autogenerated rule brought to you by yara-signator)\r\nSource: https://malpedia.caad.fkie.fraunhofer.de/details/win.snatch\r\nhttps://malpedia.caad.fkie.fraunhofer.de/details/win.snatch\r\nPage 1 of 1",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://malpedia.caad.fkie.fraunhofer.de/details/win.snatch"
	],
	"report_names": [
		"win.snatch"
	],
	"threat_actors": [
		{
			"id": "aa73cd6a-868c-4ae4-a5b2-7cb2c5ad1e9d",
			"created_at": "2022-10-25T16:07:24.139848Z",
			"updated_at": "2026-04-10T02:00:04.878798Z",
			"deleted_at": null,
			"main_name": "Safe",
			"aliases": [],
			"source_name": "ETDA:Safe",
			"tools": [
				"DebugView",
				"LZ77",
				"OpenDoc",
				"SafeDisk",
				"TypeConfig",
				"UPXShell",
				"UsbDoc",
				"UsbExe"
			],
			"source_id": "ETDA",
			"reports": null
		}
	],
	"ts_created_at": 1775434692,
	"ts_updated_at": 1775791469,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/bf1ad09784732745682181593bfbbfaf30bde9a3.pdf",
		"text": "https://archive.orkl.eu/bf1ad09784732745682181593bfbbfaf30bde9a3.txt",
		"img": "https://archive.orkl.eu/bf1ad09784732745682181593bfbbfaf30bde9a3.jpg"
	}
}