Browser fetches paste.sh loader and Google Sheets payload on crypto swap sites
This rule detects potential browser-based wallet address substitution attacks by monitoring for a specific sequence of network connections within a single browser process. It looks for connections to cryptocurrency swap platforms (SimpleSwap/SwapZone) closely followed by the retrieval of an external loader script (paste.sh) and a Google Sheets Visualization API payload, which is a known technique for injecting malicious scripts that intercept and modify XHR/fetch responses in the user's browser.
Microsoft Sentinel (KQL)

