ET DROP Spamhaus DROP Listed Traffic Inbound group 64
Sourceet/open
CreatedDecember 30, 2010
UpdatedMay 26, 2026
Classificationmisc-attack
alert ip [211.102.144.0/22,211.102.148.0/22,212.224.93.0/24,212.237.152.0/21,213.177.179.0/24,213.190.14.0/24,213.209.159.0/24,216.7.96.0/20,216.9.224.0/22,216.26.224.0/19,216.63.240.0/22,216.93.96.0/19,216.137.144.0/20,216.179.128.0/17,216.240.96.0/20,216.250.16.0/20,217.22.254.0/23,217.60.199.0/24,217.60.250.0/24,217.145.226.0/23] any -> $HOME_NET any (msg:"ET DROP Spamhaus DROP Listed Traffic Inbound group 64"; reference:url,www.spamhaus.org/drop/drop.txt; threshold:type limit, track by_src, seconds 3600, count 1; classtype:misc-attack; flowbits:set,ET.Evil; flowbits:set,ET.DROPIP; sid:2400063; rev:4719; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag Dshield, signature_severity Minor, created_at 2010_12_30, updated_at 2026_05_26;)
References
Metadata
affected productAny
attack targetAny
deploymentPerimeter
tagDshield
signature severityMinor
created at2010_12_30
updated at2026_05_26
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!