He visited the domain. It was a perfect replica of the official Minecraft launcher download page. Except the download button installed a remote access tool. “спасибо
Alex ran the file through a dynamic analyzer. The executable dropped a second-stage payload from a Pastebin URL. The payload was a PowerShell script that deobfuscated into a C2 beacon. The beacon’s domain: minecraft-updates[.]org .