qks.exe

The application qks.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from www.reqxvrvv.com and multiple other hosts.
MD5:
08d099114cf5fe9af9516db62de0577e

SHA-1:
fdd3c99cf9d3f42902c2066b926058a68dedf352

SHA-256:
38d3e53cf906fb5bcb9552d103a008901d174d69808dfab144406adbdd5007d1

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/8/2025 4:28:42 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.Qksee.Meta (M)
16.7.7.1

File size:
2.1 MB (2,196,980 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\qks.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:32Qz2D6IpUe0cfGwOt9+YbeAUhU+dJXWqc3uchs:mQz2eISdcgrHfkU8JXBc3uc+

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 5E, 80, AC, 7A, B4, F5, DF, 7B, 00, 00, 00, 00, 00, 7F, 00, 00, 00, 00, 00, 00, 00, 3B, 1F, 39, 64, BB, D6, 44, BA, 59, 07, 00, 40, 56, 58, E2, A0, CC, B5, 25, F5, 33, F5, 43, CB, C8, 7F, F4, 84, 9D, 8A, 6C, E8, ED, BA, 55, C6, 7C, EA, DA, 64, C9, 61, 0A, 59, E5, 15, 27, 71, 30, 0B, 6E, 9F, 49, C8, A9, 92, CB, 65, 7E, E5, CE, D6, E8, 72, F8, 08, 1D, 83, B3, CA, 77, 72, 94, 90, E0, 54, 35, F0, 93, 95, 56, 61, E4, 38, A6, BD, 01, 17, EE, 88, 8E, 02, CC, AF, A2, E1, 10, 7D, FD, CB...
 
[+]

The file qks.exe has been seen being distributed by the following 6 URLs.

http://113.171.224.205/.../qks.exe

http://113.171.224.175/.../qks.exe

Remove qks.exe - Powered by Reason Core Security