qks.exe

The application qks.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from 43.255.113.227 and multiple other hosts.
MD5:
62d38d0fc25f30eba624e4aebbeb9cc4

SHA-1:
418baf9ad73217b8bcb7d68ca61c5417956846e1

SHA-256:
5c2ea68bf296442b343b3548250c26877d719d15e321a11f4ab130d079c3b01a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/8/2025 4:27:17 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.Qksee.Meta (M)
16.7.7.1

File size:
2.1 MB (2,177,611 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\qks.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:n2PC0V/Xc9/pLArY37nxE8WbL+VjZnPDLoq3luRJj6no+V:nKrV/XglD37xE/UnPDLvfnoK

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 5E, B2, FC, 4D, 74, 5C, 60, 7B, 00, 00, 00, 00, 00, 7F, 00, 00, 00, 00, 00, 00, 00, C0, 5A, 43, CE, BB, D6, 44, BA, 59, 07, 00, 40, 56, 58, E2, A0, CD, 25, 3D, F5, 33, 1D, 34, E6, 6E, B9, 79, 52, CE, C9, 20, 84, 41, 1A, 85, 32, D3, ED, AC, 82, BB, 29, 36, BD, 94, E0, D5, 07, F6, C9, 82, 4E, 45, 2A, 5E, 43, 7A, 77, BA, 84, B3, D1, D3, 3E, 26, 5E, 67, 75, AE, B0, BA, E4, AA, 74, 99, B3, 85, 23, BD, F1, FA, 62, 31, 2E, 6C, 11, 56, 9F, 8F, 62, 76, 2F, 79, CF, AA, 06, 85, 84, F5, C6...
 
[+]

Entropy:
7.9999  (probably packed)

The file qks.exe has been seen being distributed by the following 6 URLs.

http://43.255.113.227/d26yaxxlnmhaem.cloudfront.net/Public/softs/qks/3.3.17/.../qks.exe

http://45.64.22.93/d26yaxxlnmhaem.cloudfront.net/Public/softs/qks/3.3.17/.../qks.exe

http://113.171.224.168/.../qks.exe

Remove qks.exe - Powered by Reason Core Security