ET DROP Spamhaus DROP Listed Traffic Inbound group 38

7.0.35.0SID: 2400037Rev: 4813EnabledDerived9 views
History
Sourceet/open
Filedrop.rules
CreatedDecember 30, 2010
UpdatedAugust 28, 2026
Classificationmisc-attack
alert ip [185.7.214.0/24,185.7.215.0/24,185.11.61.0/24,185.14.192.0/24,185.19.40.0/24,185.30.168.0/22,185.34.147.0/24,185.36.80.0/24,185.36.81.0/24,185.36.82.0/23,185.37.195.0/24,185.42.164.0/24,185.56.83.0/24,185.64.23.0/24,185.68.152.0/22,185.81.68.0/24,185.84.157.0/24,185.93.89.0/24,185.99.98.0/24,185.100.120.0/22] any -> $HOME_NET any (msg:"ET DROP Spamhaus DROP Listed Traffic Inbound group 38"; reference:url,www.spamhaus.org/drop/drop.txt; threshold:type limit, track by_src, seconds 3600, count 1; classtype:misc-attack; flowbits:set,ET.Evil; flowbits:set,ET.DROPIP; sid:2400037; rev:4813; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag Dshield, signature_severity Minor, created_at 2010_12_30, updated_at 2026_08_28;)

Metadata

affected productAny
attack targetAny
deploymentPerimeter
tagDshield
signature severityMinor
created at2010_12_30
updated at2026_08_28

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!