Major Characteristics : - Offline Encryption - Change the default values of the registry entry "HKEY_CLASSES_ROOT\mscfile\shell\open\command" and a ransomware execution using Event Viewer (eventvwr.exe) - Disable system restore (vssadmin.exe delete shadows /all /quiet)