This technical report examines the growing trend of QR code phishing, highlighting the vulnerabilities associated with QR codes that make them attractive to cybercriminals. The report outlines findings from Trustwave researchers regarding ongoing QR code phishing scams, including the identification of 18 URLs that serve as indicators of compromise (IoCs). The WhoisXML API research team conducted a thorough investigation into the DNS to uncover additional artifacts linked to these IoCs. The analysis revealed 10,000 domains with the same registrant name as the IoCs, with 10 domains flagged as malicious. Furthermore, the report details the results of a bulk WHOIS lookup, which identified 15 of the 18 domains as newly registered and spread across various registrars. The report also discusses the connections found in the DNS, including the identification of dedicated IP addresses and additional malicious domains. The findings aim to enhance understanding of the infrastructure used by threat actors in QR code phishing schemes.