Highly customized phishing attachment detected by NACE:
Hex → Base64 → URI decode → Landing URL
Disables copy, selectstart, contextmenu
Blocks dev tools via console.log override
Back-button trap using history.pushState
Stealthy, evasive — classic phishing loader behavior