qks.exe

The application qks.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from www.reqxjykn.com and multiple other hosts.
MD5:
ab94900df2835cec10f61ec4c66ebf18

SHA-1:
ea48ed3d73f5a2a04879000e8c7021f90ab98679

SHA-256:
ec1c642208ad1c21ad255ace0a453940ed09542105861224447ced8f406680ef

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 10:31:52 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.Qksee.Meta (M)
16.7.7.9

File size:
2.1 MB (2,208,984 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\qks.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:rAbXVsgwZ0oeAhSAEp3WNteDTlrnI+lxvEcdMD6Ido04RdDCqF:kLVsB+Ahh+3WNYDx8+lxvpzId8N

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 5E, FA, 0B, 03, E5, C9, EE, 7B, 00, 00, 00, 00, 00, 7F, 00, 00, 00, 00, 00, 00, 00, 07, 43, 1B, AD, BB, D6, 44, BA, 59, 07, 00, 40, 56, 58, E2, A0, CC, B5, 25, F5, 33, F5, 43, DD, E9, F4, 37, A6, 07, C0, 72, D9, F3, EA, 30, 1B, 68, C4, D6, 74, 65, 2F, C9, 77, 41, 1E, 5D, 16, 5C, 6A, 86, 95, 04, 69, 3A, 86, 5B, 27, 58, 27, 8F, A2, A2, C8, 4E, FB, BF, 12, CD, 74, 7C, 1B, 62, 24, 7C, 49, 5A, 60, 94, 24, BA, 30, 6C, A8, 6E, A7, 35, 42, DC, 11, 2E, 4E, CA, 8D, 28, 3C, D5, BF, 9C, 76...
 
[+]

The file qks.exe has been seen being distributed by the following 9 URLs.

http://113.171.224.212/.../qks.exe

http://113.171.224.169/.../qks.exe

http://113.171.224.243/.../qks.exe

http://113.171.224.165/.../qks.exe

Remove qks.exe - Powered by Reason Core Security