Base64-obfuscated C2 URL fragments in malicious proc-macro1 build.rs
Detects the exact base64-encoded URL fragments used by the malicious proc-macro1 build.rs to obscure the C2 download URL (23.254.165.112:9089) prior to fetching a remote payload.
YARA

