ET DROP Spamhaus DROP Listed Traffic Inbound group 52
Sourceet/open
CreatedDecember 30, 2010
UpdatedMay 26, 2026
Classificationmisc-attack
alert ip [200.34.135.0/24,200.34.156.0/24,200.71.124.0/22,200.189.44.0/22,200.229.31.0/24,201.148.168.0/22,201.150.28.0/22,202.12.101.0/24,202.27.100.0/22,202.40.32.0/19,202.40.64.0/18,202.46.96.0/20,202.52.38.0/24,202.59.234.0/23,202.61.128.0/18,202.61.141.0/24,202.69.136.0/21,202.78.164.0/24,202.79.173.0/24,202.95.7.0/24] any -> $HOME_NET any (msg:"ET DROP Spamhaus DROP Listed Traffic Inbound group 52"; reference:url,www.spamhaus.org/drop/drop.txt; threshold:type limit, track by_src, seconds 3600, count 1; classtype:misc-attack; flowbits:set,ET.Evil; flowbits:set,ET.DROPIP; sid:2400051; rev:4719; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag Dshield, signature_severity Minor, created_at 2010_12_30, updated_at 2026_05_26;)
References
Metadata
affected productAny
attack targetAny
deploymentPerimeter
tagDshield
signature severityMinor
created at2010_12_30
updated at2026_05_26
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!