Suspicious ntdll.dll file access by CRPx0 stager binaries (unhooking)

Detects instances where specific suspicious or known-malicious processes load 'ntdll.dll' from the 'System32' directory. This behavior is indicative of potential DLL side-loading, process injection, or evasive execution patterns where an attacker leverages legitimate system binaries to load malicious code.