n0va phishing-kit lure domain buildersouthwestlondon.com activity
Detects successful network connections to a specific domain (buildersouthwestlondon.com) where the request URL path includes the string '/cloud/'. This pattern is often indicative of downloading secondary payloads, command-and-control communication, or accessing malicious infrastructure related to a specific campaign.
Microsoft Sentinel (KQL)

