ET DROP Spamhaus DROP Listed Traffic Inbound group 58

7.0.35.0SID: 2400057Rev: 4813EnabledDerived12 views
History
Sourceet/open
Filedrop.rules
CreatedDecember 30, 2010
UpdatedAugust 28, 2026
Classificationmisc-attack
alert ip [204.86.16.0/20,204.87.199.0/24,204.87.234.0/24,204.88.160.0/20,204.89.202.0/24,204.89.224.0/24,204.91.96.0/20,204.106.128.0/18,204.106.192.0/19,204.107.132.0/24,204.107.208.0/24,204.110.8.0/21,204.110.144.0/20,204.110.176.0/21,204.110.184.0/23,204.115.112.0/22,204.115.116.0/24,204.115.128.0/21,204.126.32.0/20,204.126.48.0/21] any -> $HOME_NET any (msg:"ET DROP Spamhaus DROP Listed Traffic Inbound group 58"; reference:url,www.spamhaus.org/drop/drop.txt; threshold:type limit, track by_src, seconds 3600, count 1; classtype:misc-attack; flowbits:set,ET.Evil; flowbits:set,ET.DROPIP; sid:2400057; rev:4813; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag Dshield, signature_severity Minor, created_at 2010_12_30, updated_at 2026_08_28;)

Metadata

affected productAny
attack targetAny
deploymentPerimeter
tagDshield
signature severityMinor
created at2010_12_30
updated at2026_08_28

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!