Tox Ransomware C2 Channel Establishment with Host Encryption Activity

Detects potential execution of a Tox ransomware negotiation channel by monitoring for processes that exhibit a high rate of file writes (potential encryption activity) in conjunction with command-line arguments containing specific patterns such as a 76-character string or the 'tox://' URI scheme, which are associated with Tox ransomware client activity.