I think, 0xFF820000 is start address :
ROM:FF810774 ADR R0, aRomstarterVer3 ; "#RomStarter Ver3.10 for EC368/369\n\r"
ROM:FF810778 BL sub_FF81070C
ROM:FF81077C CMP R0, #0
ROM:FF810780 BEQ loc_FF8107AC
ROM:FF810784
ROM:FF810784 loc_FF810784 ; CODE XREF: sub_FF810758+38j
ROM:FF810784 ADR R0, aUartLoopbackSw ; "UART loopback switch ON...\n\r"
ROM:FF810788 BL sub_FF81070C
ROM:FF81078C CMP R0, #0
ROM:FF810790 BNE loc_FF810784
ROM:FF810794 ADR R0, aUartLoopback_0 ; "UART loopback switch OFF...\n\r"
ROM:FF810798 BL sub_FF811C20
ROM:FF81079C ADR R0, aRescueLoader ; "Rescue Loader\n\r"
ROM:FF8107A0 BL sub_FF811C20
ROM:FF8107A4 BL sub_FF8109A0
ROM:FF8107A8
ROM:FF8107A8 loc_FF8107A8 ; CODE XREF: sub_FF810758:loc_FF8107A8j
ROM:FF8107A8 B loc_FF8107A8
ROM:FF8107AC ; ---------------------------------------------------------------------------
ROM:FF8107AC
ROM:FF8107AC loc_FF8107AC ; CODE XREF: sub_FF810758+28j
ROM:FF8107AC LDR R4, =loc_FF820000
ROM:FF8107B0 MOV R0, R4
ROM:FF8107B4 BL 0x1D8
ps
dumping script hangs if use it for dump from address 0xff020000.