Docusign lure redirecting via MS/Google identity endpoints to NovaCookies infra

Detects phishing emails purportedly from Docusign that contain malicious links which redirect users through legitimate identity provider domains (e.g., login.microsoftonline.com, accounts.google.com) before landing on non-trusted infrastructure. This redirect-chain pattern is indicative of NovaCookies Adversary-in-the-Middle (AiTM) delivery, used to facilitate credential or session cookie theft.