Possible ClientKing beacon abusing internal proxy CONNECT authentication to known Jewelbug infrastructure

Detects a ClientKing-style beacon abusing internal proxy CONNECT authentication to reach known Jewelbug C2 infrastructure (tarotfree101.top), reusing a compromised organization's own proxy the way Jewelbug reused a major aerospace manufacturer's internal proxy.