NarwhalRAT pCloud dead-drop resolver C2 fallback traffic

Detects network traffic associated with NarwhalRAT malware utilizing the pCloud API as a command-and-control (C2) channel or dead-drop resolver. The rule monitors both HTTP requests containing specific folder identifiers and authentication parameters, as well as TLS SNI indicating connections to api.pcloud.com.