C2Looper pld.exe dropped directly in LocalAppData root

Detects the creation or renaming of a file named 'pld.exe' within the AppData Local directory. This path is frequently used by malware to masquerade as legitimate applications and establish persistence while avoiding scrutiny.