0:000> !py mona jmp -r esp -m qt5core.dll
Hold on...
[+] Command used:
!py C:\Users\user\Documents\windbg\x86\mona.py jmp -r esp -m qt5core.dll
---------- Mona command started on 2024-07-21 19:54:25 (v2.0, rev 636) ----------
[+] Processing arguments and criteria
- Pointer access level : X
- Only querying modules qt5core.dll
[+] Generating module info table, hang on...
- Processing modules
- Done. Let's rock 'n roll.
[+] Querying 1 modules
- Querying module Qt5Core.dll
- Search complete, processing results
[+] Preparing output file 'jmp.txt'
- (Re)setting logfile C:\mona\jmp.txt
[+] Writing results to C:\mona\jmp.txt
- Number of pointers of type 'xchg eax,esp # call eax' : 1
- Number of pointers of type 'call esp' : 22
- Number of pointers of type 'jmp esp' : 41
- Number of pointers of type 'push esp # ret ' : 21
[+] Results :
0x68c210a6 | 0x68c210a6 : xchg eax,esp # call eax | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68f7187b | 0x68f7187b : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68f7bcdb | 0x68f7bcdb : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68f7d343 | 0x68f7d343 : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68f84603 | 0x68f84603 : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68f857cf | 0x68f857cf : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68f86627 | 0x68f86627 : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68f866e7 | 0x68f866e7 : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68f95b33 | 0x68f95b33 : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68fa7f93 | 0x68fa7f93 : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68fad5f3 | 0x68fad5f3 : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68fb2eef | 0x68fb2eef : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68fbeda3 | 0x68fbeda3 : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68fbf033 | 0x68fbf033 : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68fbf077 | 0x68fbf077 : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68fc6b27 | 0x68fc6b27 : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68fcbfa3 | 0x68fcbfa3 : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68fdfcdb | 0x68fdfcdb : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68fe1a7f | 0x68fe1a7f : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
0x68feefdb | 0x68feefdb : call esp | {PAGE_EXECUTE_WRITECOPY} [Qt5Core.dll] ASLR: False, Rebase: False, SafeSEH: False, CFG: False, OS: False, v5.9.0.0, 0x0
... Please wait while I'm processing all remaining results and writing everything to file...
[+] Done. Only the first 20 pointers are shown here. For more pointers, open C:\mona\jmp.txt... Found a total of 85 pointers