qks.exe

The application qks.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from 113.171.224.215 and multiple other hosts.
MD5:
0aab1339b5943249921b931bb31b696f

SHA-1:
6d567b9d0b757d812410ee321e0b660229b1ce25

SHA-256:
12dbf1ffa856d62e967a71f076be0a0334fa51cd8928b08fd6aee7aa7a267314

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 7:10:48 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.Qksee.Meta (M)
16.7.7.8

File size:
2.1 MB (2,180,399 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\qks.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:IXgwCuh+isrKjiPmbMtHC+69FzGQGvVxFsrsVWN2e:IXyeiebMtHL6vKvdsrs5e

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 5E, 5F, EE, 44, F3, B0, 1E, 7B, 00, 00, 00, 00, 00, 7F, 00, 00, 00, 00, 00, 00, 00, 3A, 16, 00, 84, BB, D6, 44, BA, 59, 07, 00, 40, 56, 58, E2, A0, CC, B5, 25, F5, 33, 1D, 34, BD, BF, C9, 55, 45, 2B, A0, E4, 52, 8D, 02, 38, E9, 30, 45, DA, 49, D6, 24, C3, F2, 6D, 59, 07, A2, EA, 71, B9, E9, FA, 15, 77, 91, 25, 24, 74, 03, D4, 59, D1, 2A, 62, 97, 55, 7F, 72, 8D, B7, 2F, 81, 83, 5F, DE, F5, B8, EA, 8F, FF, 5A, 09, AA, F2, E7, D1, 97, 98, 3B, 54, 71, 2B, 45, 7A, E1, 06, 35, 99, FD...
 
[+]

The file qks.exe has been seen being distributed by the following 4 URLs.

http://113.171.224.215/.../qks.exe

http://113.171.224.175/.../qks.exe

http://113.171.224.245/.../qks.exe

Remove qks.exe - Powered by Reason Core Security