title: Potential Snatch Ransomware Activity id: 5325945e-f1f0-406e-97b8-65104d393fff status: stable description: Detects specific process characteristics of Snatch ransomware word document droppers references: - https://news.sophos.com/en-us/2019/12/09/snatch-ransomware-reboots-pcs-into-safe-mode-to-bypass-protection/ author: Florian Roth (Nextron Systems) date: 2020-08-26 modified: 2025-10-19 tags: - attack.execution - attack.t1204 - detection.emerging-threats logsource: category: process_creation product: windows detection: selection: - CommandLine|re: 'shutdown\s+/r /f /t 00' # Shutdown in safe mode immediately - CommandLine|re: 'net\s+stop SuperBackupMan' condition: selection falsepositives: - Scripts that shutdown the system immediately and reboot them in safe mode are unlikely level: high