HUNT IOC domains: DNS/web hunting (ClearFake/Vidar/AMOS etc.)

This rule detects DNS queries or network connections originating from endpoints to a list of known malicious domains associated with various malware families (ClearFake, IClickFix, AMOS, Vidar, etc.). This helps identify potential C2 communication, malicious payload delivery, or infrastructure interaction.