ET DROP Spamhaus DROP Listed Traffic Inbound group 23
Sourceet/open
CreatedDecember 30, 2010
UpdatedMay 26, 2026
Classificationmisc-attack
alert ip [111.90.140.0/23,111.90.142.0/23,111.90.156.0/24,111.90.157.0/24,111.223.244.0/24,112.90.143.0/24,112.142.0.0/15,112.142.160.0/22,112.143.0.0/19,112.213.96.0/19,113.212.128.0/19,114.134.28.0/22,114.231.216.0/22,114.239.188.0/24,115.144.69.0/24,115.167.3.0/24,115.167.64.0/24,117.18.0.0/24,117.60.11.0/24,117.120.136.0/22] any -> $HOME_NET any (msg:"ET DROP Spamhaus DROP Listed Traffic Inbound group 23"; reference:url,www.spamhaus.org/drop/drop.txt; threshold:type limit, track by_src, seconds 3600, count 1; classtype:misc-attack; flowbits:set,ET.Evil; flowbits:set,ET.DROPIP; sid:2400022; rev:4719; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag Dshield, signature_severity Minor, created_at 2010_12_30, updated_at 2026_05_26;)
References
Metadata
affected productAny
attack targetAny
deploymentPerimeter
tagDshield
signature severityMinor
created at2010_12_30
updated at2026_05_26
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!