ET DROP Spamhaus DROP Listed Traffic Inbound group 5

7.0.35.0SID: 2400004Rev: 4813EnabledDerived8 views
History
Sourceet/open
Filedrop.rules
CreatedDecember 30, 2010
UpdatedAugust 28, 2026
Classificationmisc-attack
alert ip [42.0.32.0/19,42.0.128.0/17,42.128.0.0/12,42.160.0.0/12,42.208.0.0/12,43.226.17.0/24,43.228.157.0/24,43.228.159.0/24,43.229.52.0/22,43.229.240.0/22,43.231.220.0/22,43.236.0.0/16,43.239.104.0/22,43.240.12.0/22,43.248.40.0/22,43.249.92.0/22,45.3.62.0/24,45.9.168.0/24,45.11.76.0/22,45.13.37.0/24] any -> $HOME_NET any (msg:"ET DROP Spamhaus DROP Listed Traffic Inbound group 5"; reference:url,www.spamhaus.org/drop/drop.txt; threshold:type limit, track by_src, seconds 3600, count 1; classtype:misc-attack; flowbits:set,ET.Evil; flowbits:set,ET.DROPIP; sid:2400004; rev:4813; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag Dshield, signature_severity Minor, created_at 2010_12_30, updated_at 2026_08_28;)

Metadata

affected productAny
attack targetAny
deploymentPerimeter
tagDshield
signature severityMinor
created at2010_12_30
updated at2026_08_28

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!