ET DROP Spamhaus DROP Listed Traffic Inbound group 4

7.0.35.0SID: 2400003Rev: 4813EnabledDerived7 views
History
Sourceet/open
Filedrop.rules
CreatedDecember 30, 2010
UpdatedAugust 28, 2026
Classificationmisc-attack
alert ip [36.255.98.0/24,36.255.216.0/22,36.255.236.0/22,37.49.148.0/24,37.72.140.0/24,37.77.150.0/24,37.140.251.0/24,37.156.64.0/23,38.18.13.0/24,38.92.184.0/21,38.107.120.0/21,40.183.136.0/22,41.71.128.0/17,41.71.150.0/24,41.71.222.0/24,41.71.223.0/24,41.71.224.0/24,41.71.225.0/24,41.71.226.0/24,41.71.229.0/24] any -> $HOME_NET any (msg:"ET DROP Spamhaus DROP Listed Traffic Inbound group 4"; reference:url,www.spamhaus.org/drop/drop.txt; threshold:type limit, track by_src, seconds 3600, count 1; classtype:misc-attack; flowbits:set,ET.Evil; flowbits:set,ET.DROPIP; sid:2400003; rev:4813; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag Dshield, signature_severity Minor, created_at 2010_12_30, updated_at 2026_08_28;)

Metadata

affected productAny
attack targetAny
deploymentPerimeter
tagDshield
signature severityMinor
created at2010_12_30
updated at2026_08_28

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!