ropshell> use d7c7e50f2d5d32b260ed380c475fc37f (download)
name         : ntdll.dll (i386/PE)
base address : 0x4b281000
total gadgets: 12633
ropshell> suggest "write mem"
> 0x4b2a86bd : add [ebx], eax; ret
> 0x4b3199a6 : add [ebx], esi; ret
> 0x4b2e596d : add [ebx], edi; ret
> 0x4b2ad3a4 : add [ecx], eax; pop edi; ret
> 0x4b29e135 : adc [edx], ebp; lahf ; ret
> 0x4b2e9edd : add [eax + 0x5dc03308], ecx; ret 0xc
> 0x4b38a025 : add [eax + 0x3b217501], ebp; ret
> 0x4b2b0c38 : add [ebx + 0x3b6602c1], eax; ret
> 0x4b30468e : adc [ebx + 0x33f703c7], ecx; ret
> 0x4b340462 : add [edx + 0x2b], ebx; ret
> 0x4b2f5ce7 : add [esi + 0x5b], ebx; ret
> 0x4b37d98d : add [edi + 0x5e], ebx; ret
> 0x4b2a1d6e : adc [edi + 0x16], esi; ret
> 0x4b2bcdae : adc [ebp + 1], esi; ret
> 0x4b2b43b2 : add [edi], ecx; test [ebx - 0xa000000], esp; ret
> 0x4b2c1764 : add [eax + 0x6a], edx; add al, ch; ret
> 0x4b2aee0c : add [ecx + 0x1400e3], eax; add [ebx], cl; ret
> 0x4b2d1b27 : add [edx + 0x5b0b2444], ecx; mov esp, ebp; pop ebp; ret 0x10
> 0x4b2f2d32 : add [eax], ecx; add [edx + 0x4b307170], bh; call edx; ret 8
> 0x4b2f2e62 : add [ebx], ecx; add [edx + 0x4b307170], bh; call edx; ret 0xc
> 0x4b2f3182 : add [ebx], edx; add [edx + 0x4b307170], bh; call edx; ret 0x10
> 0x4b2f2632 : add [ecx], edx; add [edx + 0x4b307170], bh; call edx; ret 0x10
> 0x4b2f3222 : add [edx], eax; add [edx + 0x4b307170], bh; call edx; ret
> 0x4b2f2752 : add [edx], ecx; add [edx + 0x4b307170], bh; call edx; ret 0xc
> 0x4b2f3322 : add [esi], eax; add [edx + 0x4b307170], bh; call edx; ret 8
> 0x4b2f2e52 : add [esi], ecx; add [edx + 0x4b307170], bh; call edx; ret 0xc
> 0x4b2f29f2 : add [edi], eax; add [edx + 0x4b307170], bh; call edx; ret 8
> 0x4b356a76 : add [edi + 0x10], eax; xor eax, eax; pop edi; pop esi; ret
> 0x4b2e542b : add [ebp + 0x88504], ecx; add [eax], al; pop ebp; ret 4
> 0x4b34e0f7 : add [edi], esi; xor eax, eax; pop edi; pop esi; pop ebx; pop ebp; ret 8
> 0x4b385ef7 : adc [eax], ebp; dec ebx; mov [edx], eax; xor eax, eax; inc eax; ret
> 0x4b2a961b : add [esi + 0x32c30000], eax; rol bl, 0x8b; call [ebx + 0x56]
> 0x4b363198 : add [eax], ebx; add [ebp + 0x2a], esi; xor al, al; pop edi; pop esi; pop ebp; ret 8
> 0x4b356a1f : adc [ebx + 9], esi; mov eax, [ebp + 8]; mov [edx], eax; add [ecx + 4], 4; xor eax, eax; pop ebp; ret 8