Do you need a of how this ransomware works?

: Running the sample in a sandbox (like Any.Run or Cuckoo) to observe file system changes.

Are you trying to encrypted by an "Ethos" variant?