AgreeToSteal Infrastructure Access

Detects suspicious network connections to 'outlook-one.vercel.app' or 'api.telegram.org' when initiated by common web browsers (msedge.exe, chrome.exe, firefox.exe) or Outlook (outlook.exe). This pattern can indicate phishing attempts, credential harvesting, or data exfiltration via Telegram bots.