@Hawkster It says it's corrupted. But no infection occurred.
If you want, I can make a test with a smaller file maybe? 10-15mb max?
Nonetheless, this thing with ransomware looks great, and it seems that there are people willing to spend money.
How I believe it actually acts: it modifies the PATH for the .pdf/.doc format. So, instead of using adobe reader/microsoft office to open, it will actually open the virus. Simple, yet effective.
However, it may go deeper and inject some code in the .pdf/docx files, not sure yet.
I'd really give it a try if I wouldn't be so petrified by "ethics", but tell me what exactly is pure white hat?