ropshell> use 437b8a73f8244efe5e49919f24c899b7 (download)
name         : ntdll.dll (x86_64/PE)
base address : 0x180001000
total gadgets: 6584
ropshell> suggest "load mem"
> 0x18006e520 : movzx eax, [rcx]; ret
> 0x1800d7b6a : mov eax, [rcx + 0x16b0]; ret
> 0x18010c3a5 : mov eax, [rdx + 0x38]; ret
> 0x180047cff : mov eax, [rdi]; add bh, dh; ret
> 0x180094bd6 : movzx ecx, [rdx]; sub eax, ecx; ret
> 0x18007da80 : mov rax, [rdx]; mov [rcx], rax; ret
> 0x18007da81 : mov eax, [rdx]; mov [rcx], rax; ret
> 0x1800a30d0 : mov rax, [rcx + 8]; and al, 0xf0; ret
> 0x180121d21 : movzx eax, [r8]; mov [r10 + 0x20], ax; ret
> 0x18006d36c : mov edx, [rcx]; add [rax + 0x33], cl; ret
> 0x1800a4409 : mov rax, [r9 + 0x30]; call rax
> 0x1800e872f : mov rbx, [r11 + 0x20]; mov rsp, r11; pop rbp; ret
> 0x18005882d : mov rsi, [r11 + 0x18]; mov rsp, r11; pop rdi; ret
> 0x1800dabd6 : mov rdi, [r11 + 0x18]; mov rsp, r11; pop rbp; ret
> 0x180087222 : mov rbp, [r11 + 0x28]; mov rsp, r11; pop rdi; ret
> 0x1800d6ae3 : mov r14, [r11 + 0x28]; mov rsp, r11; pop r15; ret
> 0x180001ee7 : mov r15, [r11 + 0x28]; mov rsp, r11; pop rbp; ret
> 0x1800ae322 : movzx eax, [r9 + 2]; xchg [rdx], ax; ret
> 0x18005882e : mov esi, [rbx + 0x18]; mov rsp, r11; pop rdi; ret
> 0x1800dabd7 : mov edi, [rbx + 0x18]; mov rsp, r11; pop rbp; ret
> 0x180087223 : mov ebp, [rbx + 0x28]; mov rsp, r11; pop rdi; ret
> 0x180067671 : mov rax, [rdx + 0x38]; mov [rdx + 0x38], rcx; ret
> 0x180085c49 : mov rcx, [rax + 0x48]; cmp [rip + 0xf971c], rcx; sete al; ret
> 0x1800fcffd : mov rcx, [r10 + 0x18]; mov [r9], rcx; mov rax, r11; ret
> 0x1800e340c : mov rdi, [rbp + 0x58]; lea rsp, [rbp + 0x30]; pop rbp; ret
> 0x1800d91f0 : mov r12, [r11 + 0x38]; mov rsp, r11; pop r15; pop r14; pop r13; ret
> 0x1800dfa0f : mov r13, [r11 + 0x38]; mov rsp, r11; pop r15; pop r14; pop rbp; ret
> 0x1800812cd : mov r14, [rbp + 0x48]; lea rsp, [rbp + 0x20]; pop rbp; ret
> 0x1800a35cf : mov r15, [rcx + 0x30]; mov rbp, [rcx - 8]; add rsp, 0x138; ret
> 0x180085c4a : mov ecx, [rax + 0x48]; cmp [rip + 0xf971c], rcx; sete al; ret
> 0x1800fcffe : mov ecx, [rdx + 0x18]; mov [r9], rcx; mov rax, r11; ret
> 0x1800812ce : mov esi, [rbp + 0x48]; lea rsp, [rbp + 0x20]; pop rbp; ret
> 0x1800a35d0 : mov edi, [rcx + 0x30]; mov rbp, [rcx - 8]; add rsp, 0x138; ret
> 0x1800e340d : mov edi, [rbp + 0x58]; lea rsp, [rbp + 0x30]; pop rbp; ret
> 0x18010c37e : movzx ecx, [r9]; add r8d, ecx; mov [rdx], r9; mov eax, r8d; ret
> 0x1800a5df9 : mov rbp, [rcx + 0x18]; mov rsp, [rcx + 0x10]; jmp rdx
> 0x1800a4463 : mov edx, [rax + 0x48]; mov [r9 + 0x48], r10d; mov eax, 3; ret
> 0x1800a5dfa : mov ebp, [rcx + 0x18]; mov rsp, [rcx + 0x10]; jmp rdx
> 0x18010ce6b : mov eax, [r9]; mov rbx, [rsp + 8]; mov rdi, [rsp + 0x10]; ret
> 0x1800ac8c4 : mov rsi, [rbp + 0x140]; lea rsp, [rbp + 0x110]; pop r14; pop rdi; pop rbp; ret
> 0x18010cfa6 : mov rax, [r10 + 0x50]; inc r9w; movzx ecx, r9w; movzx eax, [rax + rcx*2]; ret
> 0x180092cc4 : mov rcx, [rdx + rcx]; bswap rax; bswap rcx; cmp rax, rcx; sbb eax, eax; sbb eax, -1; ret
> 0x1800e3408 : mov rbx, [rbp + 0x50]; mov rdi, [rbp + 0x58]; lea rsp, [rbp + 0x30]; pop rbp; ret
> 0x180078d09 : mov r8, [rdx + 8]; sub r8, [rcx + 0x18]; xor eax, eax; test r8, r8; sete al; ret
> 0x1800a35cb : mov r14, [rcx + 0x28]; mov r15, [rcx + 0x30]; mov rbp, [rcx - 8]; add rsp, 0x138; ret
> 0x1800e3409 : mov ebx, [rbp + 0x50]; mov rdi, [rbp + 0x58]; lea rsp, [rbp + 0x30]; pop rbp; ret
> 0x180034c27 : movzx ecx, [rbx + 0x1c]; sub cx, [r9 + 0x1c]; not cx; mov [r9 + 0x1c], cx; ret
> 0x180034c26 : movzx ecx, [r11 + 0x1c]; sub cx, [r9 + 0x1c]; not cx; mov [r9 + 0x1c], cx; ret
> 0x1800a35cc : mov esi, [rcx + 0x28]; mov r15, [rcx + 0x30]; mov rbp, [rcx - 8]; add rsp, 0x138; ret
> 0x1800a5ecf : mov r11, [rdx]; mov rdx, [rdx + r8 - 8]; mov [rcx], r11; mov [rcx + r8 - 8], rdx; ret
> 0x1800a5ed0 : mov ebx, [rdx]; mov rdx, [rdx + r8 - 8]; mov [rcx], r11; mov [rcx + r8 - 8], rdx; ret
> 0x1800a5df5 : mov rdx, [rcx + 0x50]; mov rbp, [rcx + 0x18]; mov rsp, [rcx + 0x10]; jmp rdx
> 0x1800a5df6 : mov edx, [rcx + 0x50]; mov rbp, [rcx + 0x18]; mov rsp, [rcx + 0x10]; jmp rdx
> 0x1800a35c7 : mov r13, [rcx + 0x20]; mov r14, [rcx + 0x28]; mov r15, [rcx + 0x30]; mov rbp, [rcx - 8]; add rsp, 0x138; ret
> 0x1800a445a : mov r10, [rax + 0x40]; mov [r9 + 0x40], r10; mov r10d, [rax + 0x48]; mov [r9 + 0x48], r10d; mov eax, 3; ret
> 0x18008ad9e : mov eax, [r10 + 0xa0]; and [r10 + 0x64], 0; mov [r10 + 0x68], eax; mov rax, [r9 + 0x68]; mov [r10 + 0x78], rax; ret
> 0x1800a35c3 : mov r12, [rcx + 0x18]; mov r13, [rcx + 0x20]; mov r14, [rcx + 0x28]; mov r15, [rcx + 0x30]; mov rbp, [rcx - 8]; add rsp, 0x138; ret
> 0x1801017b6 : movsxd rcx, [r8 + 0x18]; movups xmm0, xmm[rax + r9]; movups xmm[rcx + rdx], xmm0; movsd xmm1, [rax + r9 + 0x10]; xor eax, eax; movsd [rcx + rdx + 0x10], xmm1; ret