TA419 Known Credential-Phishing or Lookalike Sender Domain Queried

Detects DNS queries, HTTP host headers, and TLS SNI traffic associated with known credential-phishing domains used by the threat actor TA419. The rule monitors for communication to a specific list of domains identified as malicious or used in phishing campaigns.