Removed rule. This rule is known, but it is no longer present in its source. Showing the last known version.Removed: Aug 3, 2026, 8:22 PM

ET COMPROMISED Known Compromised or Hostile Host Traffic group 19

7.0.35.0SID: 2500036Rev: 7701EnabledDerived22 viewsHistory
Sourceet/open
Filecompromised.rules
CreatedApril 28, 2011
UpdatedJuly 31, 2026
Classificationmisc-attack
alert ip [52.37.240.15,52.53.230.4,52.8.62.56,54.177.2.21,54.193.112.103,54.218.230.32,58.48.53.254,59.15.64.97,59.24.28.114,60.173.164.3,62.60.130.219,64.226.126.224,64.227.136.19,64.89.161.91,64.89.162.146,64.89.162.37,64.89.162.38,65.49.139.223,68.183.122.41,71.206.190.209,77.83.72.79,77.90.185.20,79.72.57.232,82.165.175.206,83.194.93.43,83.97.78.224,85.11.167.228,87.120.84.66,88.151.33.203,89.126.211.166] any -> $HOME_NET any (msg:"ET COMPROMISED Known Compromised or Hostile Host Traffic group 19"; reference:url,danger.rulez.sk/projects/bruteforceblocker/blist.php; threshold:type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2500036; rev:7701; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag COMPROMISED, signature_severity Major, created_at 2011_04_28, updated_at 2026_07_31;)

Metadata

affected productAny
attack targetAny
deploymentPerimeter
tagCOMPROMISED
signature severityMajor
created at2011_04_28
updated at2026_07_31

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!