YOOO it got the c2 URL this time!
"This is a Rust-compiled DLL sideloading proxy masquerading as CRYPTBASE.dll, designed to be loaded by CPUID's HWMonitor (hwmonitor_1.63). On DLL_PROCESS_ATTACH, it spawns a thread that suspends the main thread, then launches the core payload thread which decodes an embedded ~360KB encrypted payload from the oversized .rdata section (1.98MB), patches in a C2 callback URL (https[:]//welcome[.]supp0v3[.]com/d/callback) with campaign identifiers (tag: tbs, referrer: monitor3), allocates RWX memory via VirtualAlloc, copies the decoded shellcode, and executes it via function pointer call. Meanwhile, the real CRYPTBASE.dll is loaded from System32 to proxy legitimate API calls transparently, maintaining the appearance of normal HWMonitor operation."