Potential Arbitrary File Download Via Cmdl32.EXE — Detection Rule

Detects execution of Cmdl32 with the "/vpn" and "/lan" flags. Attackers can abuse this utility in order to download arbitrary files via a configuration file. Inspect the location and the content of the file passed as an argument in order to determine if it is suspicious.

Read the full analysis on IntelFusions