qks.exe

The application qks.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from d26yaxxlnmhaem.cloudfront.net and multiple other hosts.
MD5:
c7f44af5de01dc22ded64edd38528648

SHA-1:
f8852baae7231c9b216c4d43c9921d503e3eb80a

SHA-256:
539fb823178232bc570050579e3b916713fff915baf0ac360aeb85ee350ca94c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/8/2025 4:55:08 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.Qksee (M)
16.7.19.7

File size:
2.1 MB (2,199,279 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\qks.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:QDJhdLcf4GXp4wFkM5cC/1yTxc11HB3XyL/QGUtBN/:Q1hmfBXpcM50T2dVXQXUN/

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 5E, EA, 79, D5, 45, F0, D4, 7B, 00, 00, 00, 00, 00, 7F, 00, 00, 00, 00, 00, 00, 00, 36, 43, 9C, 0D, BB, D6, 44, BA, 59, 07, 00, 40, 56, 58, E2, A0, CD, 25, 3D, F5, 33, F5, 43, CB, 72, 2D, 37, A6, 07, C0, 72, D9, F3, EA, 30, 1B, 68, C4, D6, 74, 65, 2F, C9, 77, 41, 1E, 5D, 16, 5C, 6A, 86, 95, 04, 69, 3A, 86, 5B, 27, 58, 27, 8F, A2, A2, C8, 4E, FB, BF, 12, CD, 74, 7C, 1B, 62, 24, 7C, 49, 5A, 60, 94, 24, BA, 30, 6C, A8, 6E, A7, 35, 42, DC, 11, 2E, 4E, CA, 8D, 28, 3C, D5, BF, 9C, 76...
 
[+]

The file qks.exe has been seen being distributed by the following 6 URLs.

http://d26yaxxlnmhaem.cloudfront.net/Public/softs/qks/3.3.11/.../qks.exe

http://113.171.224.171/.../qks.exe

http://d26yaxxlnmhaem.cloudfront.net/Public/softs/qks/3.3.23/.../qks.exe

http://113.171.224.212/.../qks.exe

Remove qks.exe - Powered by Reason Core Security