DNS/network connections to ted/curlRAT C2 domains

This rule detects network communication (via DNS queries, web logs, or device network events) with a list of known malicious domains associated with Command and Control (C2) activity.