Central Asia-targeting cluster: service-themed subdomains on natcommunzu/kginfoc

Detects network connection events to known domains and subdomains associated with the SilkParasite threat actor. The rule specifically monitors for connections to specific parent domains (natcommunzu.com, kginfocom.com, mfa-uz.com) and subdomains utilizing service-oriented naming patterns (e.g., mail, service, help, storage, support, microsoft, post) commonly used by this actor for command and control infrastructure.