IOC Radar
DomainMediumSignal 12/100

www.southstar-holdings.com

First Seen
Mar 31, 2025
Last Seen
May 10, 2025
Mar 31
First Seen
442d ago
May 10
Last Seen
402d ago
2
Reports
source reports
12%
Confidence
medium
Found in 2 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
12%
Signal Score
12 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

19 techniques

Feed Intelligence Summary

2 reports12% confidence
2
Source reports
12%
Confidence score
Category tags
bankingbotnetclone firmcommand and controlcredential harvestingcredential theftcredit card servicescyber threatsdata exfiltrationdistributed attacksfakefake investment opportunityfinancefinance and insurancefinancial crimefinancial servicesfinancial technologyfraudindicatorinvestment fraudinvestment scammalicious softwaremalwarenetworkpayment processingphishingphishing attackprocess injectionrecovery fraudregulatory alertresearchedscamsocial engineeringt1055t1071t1071.001t1078t1192t1204.002t1486t1496t1499.001t1499.002t1499.003t1565t1566t1566.001t1566.002t1566.003t1567.001t1598t1598.003warning listwealth management

Activity Timeline

1 total obs
May 10May 10

Threat Activity Heatmap

Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated

The domain www.southstar-holdings.com has emerged as a significant indicator of compromise (IOC) associated with multiple cyber threats, including botnet activity, malware distribution, and phishing campaigns. First observed on March

Threat ScoreLow Risk
12
SIGNAL
Signal Score
12%
Confidence
2
Reports
First seenMar 31, 2025
Last seenMay 10, 2025

VirusTotal

Not checked

WHOIS

registrar
ENOM, INC.
description
The IOSCO platform "https://www.iosco.org/i-scan/" consolidates scam/fraud warnings and IoC from worldwide financial regulators.
raw
Domain Name: SOUTHSTAR-HOLDINGS.COM Registrar: ENOM, INC. Sponsoring Registrar IANA ID: 48 Whois Server: whois.enom.com Referral URL: http://www.enom.com Name Server: DNS1.NAME-SERVICES.COM Name Server: DNS2.NAME-SERVICES.COM Name Server: DNS3.NAME-SERVICES.COM Name Server: DNS4.NAME-SERVICES.COM Name Server: DNS5.NAME-SERVICES.COM Status: clientTransferProhibited https://www.icann.org/epp#clientTransferProhibited Updated Date: 04-may-2015 Creation Date: 11-may-2013 Expiration Date: 11-may-2016 Registry Domain ID: 1800575124_DOMAIN_COM-VRSN Registrar WHOIS Server: whois.enom.com Registrar URL: www.enom.com Updated Date: 2015-06-10T15:25:20.00Z Creation Date: 2013-05-11T18:40:00.00Z Registrar Registration Expiration Date: 2016-05-11T17:40:34.00Z Registrar IANA ID: 48 Domain Status: clientTransferProhibited https://www.icann.org/epp#clientTransferProhibited Registrant Country: US Registrant Email: [REDACTED]@WHOISPRIVACYPROTECT.COM Admin Organization: WHOIS PRIVACY PROTECTION SERVICE, INC. Admin City: KIRKLAND Admin State/Province: WA Admin Postal Code: 98083 Admin Country: US Admin Email: [REDACTED]@WHOISPRIVACYPROTECT.COM Tech Organization: WHOIS PRIVACY PROTECTION SERVICE, INC. Tech City: KIRKLAND Tech State/Province: WA Tech Postal Code: 98083 Tech Country: US Tech Email: [REDACTED]@WHOISPRIVACYPROTECT.COM DNSSEC: unSigned Registrar Abuse Contact Email: [email protected] Registrar Abuse Contact Phone: +1.4252982646

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 1 year ago
Appeared in 2 threat reports