TF-1931048
high
📛 Threat Title
Tsundere: ip:port combination that is used for botnet Command&control (C&C) 2.26.29.7:443
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: ip:port combination that is used for botnet Command&control (C&C). Attributed malware: Tsundere (aliases: DinDoor). Confidence: 75. Observed port: 443. First seen: 2026-09-23 19:45:15 UTC. Last seen: 2026-09-23 23:44:50 UTC. Reporter: abuse_ch. Tags: DinDoor, drb-ra.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
2.26.29.7
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/2.26.29.7
IOC database
- Type
- ipv4
- Value
2.26.29.7- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Tsundere
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/2.26.29.7
References (2)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a botnet command&control server (C&C). IOC type: ip:port combination that is used for botnet Command&control (C&C). Attributed malware: Tsundere (aliases: DinDoor). Confidence: 75. Observed port: 443. First seen: 2026-09-23 19:45:15 UTC. Reporter: abuse_ch. Tags: DinDoor, drb-ra.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.