Koxic Ransomware Deep-dive Analysis
ID: 9d3bee19-029f-5652-a906-d1a2747a4d11
STIX ID: report--9d3bee19-029f-5652-a906-d1a2747a4d11
Feed Name: Cyble Blog
Threat Score
This report analyzes the Koxic ransomware sample, detailing its infection and post-compromise behaviors — including disabling Windows Defender, terminating security processes, deleting shadow copies, disabling database services, stealing system information, privilege manipulation, and encrypting files with a ".KOXIC_KLIBD" extension — and provides IOCs (SHA256, extortion email), MITRE ATT&CK mappings, and mitigation recommendations for backups, patching, and endpoint protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
