Ransomware uses same template of the site for a victim as Cerber did. It does not delete the original copy, but just encrypts all the data in the background. Names of the encrypted files are not changed only new extensions are added at the end, which are randomly generated on each run. Every file is encrypted with the same key, which means the same plaintext produces the same ciphertext. The application communicates with its C&C, that is hosted on a Tor-based site: It sends sets of Base64-encrypted data.”]
Source: https://blog.malwarebytes.com/threat-analysis/2016/11/princess-ransomware/