Mobef Ransomware takes control of a computer by encrypting its victim's files and then demanding a ransom to decrypt those files. It changes the extensions of the affected files and displays a ransom note in the form of text and HTML files dropped into the folders containing the encrypted files. It also turns the wallpaper image of the affected computer into a ransom note with payment instructions. This Ransomware encrypts with an RSA-2048 key and adds file extensions to .KEYH0LES or .KEYZ