ET DROP Spamhaus DROP Listed Traffic Inbound group 27
Sourceet/open
CreatedDecember 30, 2010
UpdatedMay 26, 2026
Classificationmisc-attack
alert ip [138.249.40.0/22,139.183.192.0/18,140.82.64.0/19,140.82.96.0/20,140.222.0.0/16,141.98.8.0/24,141.98.9.0/24,141.98.10.0/24,141.98.11.0/24,141.178.0.0/16,141.206.128.0/20,142.102.0.0/16,143.92.32.0/20,143.92.43.0/24,143.92.48.0/20,143.222.0.0/16,144.48.4.0/24,144.215.0.0/16,145.231.0.0/16,146.3.0.0/16] any -> $HOME_NET any (msg:"ET DROP Spamhaus DROP Listed Traffic Inbound group 27"; reference:url,www.spamhaus.org/drop/drop.txt; threshold:type limit, track by_src, seconds 3600, count 1; classtype:misc-attack; flowbits:set,ET.Evil; flowbits:set,ET.DROPIP; sid:2400026; rev:4719; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag Dshield, signature_severity Minor, created_at 2010_12_30, updated_at 2026_05_26;)
References
Metadata
affected productAny
attack targetAny
deploymentPerimeter
tagDshield
signature severityMinor
created at2010_12_30
updated at2026_05_26
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!