ET DROP Spamhaus DROP Listed Traffic Inbound group 48
Sourceet/open
CreatedDecember 30, 2010
UpdatedMay 26, 2026
Classificationmisc-attack
alert ip [198.244.46.0/24,198.246.162.0/24,198.252.32.0/19,198.252.174.0/24,199.1.24.0/21,199.5.152.0/23,199.5.194.0/24,199.5.229.0/24,199.26.137.0/24,199.26.207.0/24,199.26.251.0/24,199.33.146.0/24,199.33.222.0/24,199.34.128.0/18,199.38.0.0/21,199.38.252.0/22,199.59.8.0/21,199.67.8.0/21,199.71.192.0/20,199.73.64.0/20] any -> $HOME_NET any (msg:"ET DROP Spamhaus DROP Listed Traffic Inbound group 48"; reference:url,www.spamhaus.org/drop/drop.txt; threshold:type limit, track by_src, seconds 3600, count 1; classtype:misc-attack; flowbits:set,ET.Evil; flowbits:set,ET.DROPIP; sid:2400047; rev:4719; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag Dshield, signature_severity Minor, created_at 2010_12_30, updated_at 2026_05_26;)
References
Metadata
affected productAny
attack targetAny
deploymentPerimeter
tagDshield
signature severityMinor
created at2010_12_30
updated at2026_05_26
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!