Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Nationalman] 'ImagePath' = '<SYSTEM32>\boxlou.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Nationalman] 'Start' = '00000002'
- '<SYSTEM32>\boxlou.exe'
- boxlou.exe
- <SYSTEM32>\boxlou.exe
- 'er####ig.ddns.net':8080
- DNS ASK er####ig.ddns.net