What are some cool things that are possible? - extract resources I guess. Is this Russian program trust worthy.
In my experience, messing with PE files is useful in a few areas:
- Compiler Development (PE files tell Windows how to load your code into memory, what resources they need/provide, and how to execute your code, etc)
- Reverse Engineering (Extracting the above info, plus locating executable files in memory and dumping them back to disk if they're e.g. packed)
- Game Cheating/Malware (You can simulate the PE loading process to turn e.g. a DLL into what basically amounts to shellcode, allowing you to skip putting your stuff on disk, to make your payloads harder to locate in memory, and to write custom obfuscation as part of the loading process)
There might be more uses I'm not thinking of, but those are the three I have experience with. It's a handy bit of trivia to know if you like dicking around w/ systems-level stuff in Windows for sure.Probably doesn't need to be said, but just in case PE is how Windows formats .exe, .dll, .sys, etc executable files.
It's basically the counterpart of ELF (Executable and Linkable Format) files, but on Windows.
Ghidra probably the most powerful. The PE structures are public, every compiler, binutil or decompiler has it.
[0]: https://www.virustotal.com/gui/url/826fca3edb8d883bb9710cabb...
Yes, it's guaranteed to have been backdoored by the NSA.