C2Looper Secondary Payload Dropped as pld.exe in AppData\Local

Detects the C2Looper secondary payload dropped as pld.exe under %LocalAppData%, typically staged as a ransomware precursor after backdoor check-in.