ET DROP Spamhaus DROP Listed Traffic Inbound group 59

7.0.35.0SID: 2400058Rev: 4813EnabledDerived7 views
History
Sourceet/open
Filedrop.rules
CreatedDecember 30, 2010
UpdatedAugust 28, 2026
Classificationmisc-attack
alert ip [204.128.180.0/24,204.130.16.0/20,204.130.134.0/24,204.130.195.0/24,204.140.104.0/21,204.140.112.0/21,204.140.120.0/22,204.146.240.0/20,204.147.64.0/21,204.147.96.0/20,204.147.240.0/20,204.153.116.0/22,204.153.160.0/23,204.153.196.0/22,204.155.80.0/21,204.155.88.0/22,204.155.92.0/23,204.155.94.0/24,204.178.16.0/20,204.179.64.0/20] any -> $HOME_NET any (msg:"ET DROP Spamhaus DROP Listed Traffic Inbound group 59"; reference:url,www.spamhaus.org/drop/drop.txt; threshold:type limit, track by_src, seconds 3600, count 1; classtype:misc-attack; flowbits:set,ET.Evil; flowbits:set,ET.DROPIP; sid:2400058; rev:4813; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag Dshield, signature_severity Minor, created_at 2010_12_30, updated_at 2026_08_28;)

Metadata

affected productAny
attack targetAny
deploymentPerimeter
tagDshield
signature severityMinor
created at2010_12_30
updated at2026_08_28

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!