Clipboard hijack via browser after Google Sheets loader / paste.sh fetch

This rule detects potential web skimmer activity where a user's browser performs a network connection to known payload delivery hosts (e.g., paste.sh or Google Sheets API) followed by a clipboard modification event on the same device within a one-hour window. This behavior is consistent with malicious scripts attempting to replace copied cryptocurrency wallet addresses with an attacker-controlled address.