TA419 TLS connection to known redirect/AitM phishing domain (OneDrive spoof chain)

Detects outbound network connections (HTTPS/TLS) to known malicious domains used by TA419 for AitM (Adversary-in-the-Middle) phishing campaigns. These domains are identified as part of a spoofed OneDrive document/file sharing theme intended to steal user credentials.