Kothamine dropper: cphc811-ui repo fetch correlated with dropped payload

This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.