ET DROP Spamhaus DROP Listed Traffic Inbound group 22
Sourceet/open
CreatedDecember 30, 2010
UpdatedMay 26, 2026
Classificationmisc-attack
alert ip [104.193.228.0/22,104.232.96.0/20,104.244.56.0/21,104.244.80.0/22,104.250.163.0/24,104.250.164.0/24,104.251.180.0/22,106.48.64.0/18,106.95.0.0/16,107.155.224.0/22,107.182.240.0/20,108.164.0.0/20,108.164.128.0/17,109.120.136.0/24,109.202.104.0/24,109.238.86.0/23,110.34.48.0/22,110.34.56.0/22,110.44.144.0/20,110.48.0.0/18] any -> $HOME_NET any (msg:"ET DROP Spamhaus DROP Listed Traffic Inbound group 22"; reference:url,www.spamhaus.org/drop/drop.txt; threshold:type limit, track by_src, seconds 3600, count 1; classtype:misc-attack; flowbits:set,ET.Evil; flowbits:set,ET.DROPIP; sid:2400021; rev:4719; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag Dshield, signature_severity Minor, created_at 2010_12_30, updated_at 2026_05_26;)
References
Metadata
affected productAny
attack targetAny
deploymentPerimeter
tagDshield
signature severityMinor
created at2010_12_30
updated at2026_05_26
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!