It looks like the IPs involved may be linked to a ransomware group. I think what they're doing is fingerprinting patching status of AnyConnect.