ET DROP Spamhaus DROP Listed Traffic Inbound group 42
Sourceet/open
CreatedDecember 30, 2010
UpdatedMay 26, 2026
Classificationmisc-attack
alert ip [192.234.189.0/24,192.234.220.0/24,192.245.101.0/24,192.245.188.0/24,192.245.248.0/24,192.251.231.0/24,192.252.16.0/20,192.252.176.0/20,192.253.224.0/20,192.253.248.0/24,193.3.164.0/24,193.3.191.0/24,193.5.251.0/24,193.24.123.0/24,193.26.115.0/24,193.30.144.0/20,193.30.241.0/24,193.32.66.0/23,193.32.162.0/24,193.46.255.0/24] any -> $HOME_NET any (msg:"ET DROP Spamhaus DROP Listed Traffic Inbound group 42"; reference:url,www.spamhaus.org/drop/drop.txt; threshold:type limit, track by_src, seconds 3600, count 1; classtype:misc-attack; flowbits:set,ET.Evil; flowbits:set,ET.DROPIP; sid:2400041; rev:4719; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag Dshield, signature_severity Minor, created_at 2010_12_30, updated_at 2026_05_26;)
References
Metadata
affected productAny
attack targetAny
deploymentPerimeter
tagDshield
signature severityMinor
created at2010_12_30
updated at2026_05_26
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!