TA419 IOC sweep: phishing domains, VPS IP, AitM URL, sender addresses

This rule detects network communication, DNS queries, email interactions, and URL clicks associated with known TA419 threat actor infrastructure. It monitors multiple telemetry sources to identify indicators of compromise (IOCs) such as specific domains, IP addresses, and email addresses.