This TTP will create a new process in a suspended state, create a clean version of `ntdll.dll`, and overwrite the `ntdll.dll` from the current process to unhook it. After `ntdll.dll` is unhooked, the shellcode is executed to spawn calc.exe.
