Technical Information
- '<SYSTEM32>\msiexec.exe' /i "%TEMP%\anyconnect-win-4.5.02033-core-vpn-predeploy-k9.msi"
- '<SYSTEM32>\schtasks.exe' /Create /TN "OXPZYZ\OXPZYZ" /XML "%APPDATA%\OXPZYZ\a88888.xml"
- %APPDATA%\Imminent\Monitoring\network.dat
- %APPDATA%\Imminent\Monitoring\system.dat
- %TEMP%\anyconnect-win-4.5.02033-core-vpn-predeploy-k9.msi
- %APPDATA%\OXPZYZ\OXPZYZ.exe
- %APPDATA%\OXPZYZ\a88888.xml
- %APPDATA%\Imminent\Logs\21-11-2017
- %APPDATA%\OXPZYZ\a88888.xml
- 'he####sk.ugent.be':80
- 'wp#d':80
- '18#.#9.10.30':443
- http://he####sk.ugent.be/vpn/download/anyconnect-win-4.5.02033-core-vpn-predeploy-k9.msi
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK he####sk.ugent.be
- DNS ASK wp#d