TA419 DNS lookup to lookalike organization-impersonation domain

Detects DNS queries and TLS SNI traffic associated with known lookalike domains used by the threat actor TA419 for organization impersonation, which are commonly utilized in spearphishing campaigns.