ropshell> use eafc3f67a1602eb1d35dde313578ab63 (download) name : ntdll.dll (x86_64/PE) base address : 0x180001000 total gadgets: 6464
ropshell> suggest "write mem" > 0x180032a58 : add [rbx], edi; ret > 0x18007186d : add [rdi], ecx; ret > 0x18007186c : add [r15], ecx; ret > 0x18008634d : add [rax + 0xf], ecx; ret > 0x1800766fa : add [rax + 1], edi; ret > 0x180074a66 : add [rbx + 0x17401f8], eax; ret > 0x18010f0a7 : adc [rcx + 0x23], eax; ret > 0x18008a40f : adc [rdx + 0x10], ecx; ret > 0x1800b658e : add [rbp + 3], ecx; ret > 0x180015b69 : adc [rbp + 1], esi; ret > 0x180066c96 : add [r9 + 0xf], eax; ret > 0x18008bf38 : add [rax], r8; add rsp, 0x48; ret > 0x1800f7e52 : add [rax], ebx; bt eax, ecx; setb al; ret > 0x1800fb6b0 : add [rdx], esi; ror [rax - 0x7d], 0xc4; ret > 0x18001fe4f : add [rcx], eax; imul rax, rcx; shr rax, 0x38; ret > 0x180083240 : add [rbx + 3], esi; mov [rcx], r8d; ret > 0x180071b22 : add [r13 + 0x88504], ecx; add [rax], al; ret > 0x1800b8622 : add [rsi], ebp; clc ; jmp [rsi - 0x77] > 0x18000339b : adc [rdx], ecx; add bl, al; lea rax, [rip + 0x542a]; ret > 0x180071b45 : add [rdx + 9], esi; xor eax, eax; cmp [rcx], r8d; seta al; ret > 0x18008a407 : adc [rdx], eax; movups xmm1, xmm[r9 + 0x10]; movups xmm[rdx + 0x10], xmm1; ret > 0x1800f5ec2 : adc [rdx + 0x4b0], eax; movups xmm1, xmm[r9 + 0x4c0]; movups xmm[rdx + 0x4c0], xmm1; ret > 0x18004825c : add [rbx + 0x2418902], ecx; movzx eax, [rdx + 4]; mov [rcx + 6], ax; xor eax, eax; ret > 0x1801088bc : add [rax + 0x48], esi; mov eax, [rip + 0x57b4a]; mov r9, [rip + 0x74733]; call r9 > 0x18005890c : add [rbx], ebp; rol [rcx - 0x77], 1; add cl, [rbx + 0x5c8b48c2]; and al, 8; mov rsi, [rsp + 0x10]; ret > 0x18005890b : add [r11], ebp; rol [rcx - 0x77], 1; add cl, [rbx + 0x5c8b48c2]; and al, 8; mov rsi, [rsp + 0x10]; ret > 0x18008ff3d : add [rcx + 0x46894101], esi; mov r8d, [rbx + rdx*8 + 0xc]; mov rdx, r13; add r8, r15; call r8 > 0x18005cc8b : add [rcx + 0x18], rax; mov eax, [rcx + 0x10]; mov [rcx + rax*8 + 0x20], r8; mov eax, edx; inc [rcx + 0x10]; ret