IOC Report
https://goqr.me/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 36
Web Open Font Format, TrueType, length 26588, version 1.0
downloaded
Chrome Cache Entry: 37
HTML document, Unicode text, UTF-8 text, with very long lines (1082)
downloaded
Chrome Cache Entry: 38
ASCII text, with very long lines (57981)
downloaded
Chrome Cache Entry: 39
Web Open Font Format, TrueType, length 24696, version 1.0
downloaded
Chrome Cache Entry: 40
PNG image data, 180 x 180, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 41
PNG image data, 180 x 180, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 42
Web Open Font Format, TrueType, length 24324, version 1.0
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=1988,i,538960023989471502,110857662081935292,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://goqr.me/"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://goqr.me/
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2112 --field-trial-handle=1852,i,18311815613419120576,11550976993936465481,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://goqr.me/
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Images/zazzle/zazzle_button.png
162.55.210.124
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Images/zazzle/zazzle_mug.png
162.55.210.124
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Images/qr_loading.gif
162.55.210.124
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Images/qr_default.png
162.55.210.124
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Fonts/general_foundicons.ttf
162.55.210.124
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Fonts/Titillium/titillium-bold-webfont.woff
162.55.210.124
https://www.zazzle.com/?rf=238299094483492343
unknown
https://goqr.me/
162.55.210.124
https://buy-me-a.coffee/paypal/coffee-donation-goQR.me/
unknown
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Stylesheets-built/app-1.3.0.css
162.55.210.124
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Fonts/Titillium/titillium-bold-webfont.ttf
162.55.210.124
https://www.denso-wave.com/en/
unknown
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Fonts/general_foundicons.woff
162.55.210.124
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Fonts/Titillium/titillium-regular-webfont.woff
162.55.210.124
http://jqueryui.com
unknown
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Images/zazzle/zazzle_tshirt.png
162.55.210.124
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Images/qr_nodata.png
162.55.210.124
http://jqueryui.com/themeroller/?tr%26ffDefault=Helvetica%2CArial%2Csans-serif&fwDefault=normal&fsDe
unknown
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Images/qr_error.png
162.55.210.124
http://goqr.me/
162.55.210.124
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Images/zazzle/zazzle_businesscard.png
162.55.210.124
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Images/Flags/de.png
162.55.210.124
https://goqr.me/_Resources/Static/Packages/GoQrMe.Ui/Fonts/Titillium/titillium-regularitalic-webfont.woff
162.55.210.124
There are 13 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
goqr.me
162.55.210.124
www.google.com
142.250.185.196
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
217.20.57.18
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
142.250.185.196
www.google.com
United States
162.55.210.124
goqr.me
United States
192.168.2.4
unknown
unknown