ET DROP Spamhaus DROP Listed Traffic Inbound group 19

7.0.35.0SID: 2400018Rev: 4816EnabledDerived5 views
History
Sourceet/open
Filedrop.rules
CreatedDecember 30, 2010
UpdatedAugust 31, 2026
Classificationmisc-attack
alert ip [103.7.198.0/23,103.12.220.0/22,103.13.140.0/22,103.19.116.0/22,103.19.188.0/22,103.20.72.0/22,103.20.156.0/22,103.23.12.0/22,103.24.0.0/22,103.25.88.0/22,103.27.248.0/22,103.29.120.0/22,103.30.12.0/22,103.30.40.0/22,103.32.0.0/16,103.32.132.0/22,103.34.0.0/16,103.36.64.0/22,103.37.118.0/24,103.39.108.0/22] any -> $HOME_NET any (msg:"ET DROP Spamhaus DROP Listed Traffic Inbound group 19"; reference:url,www.spamhaus.org/drop/drop.txt; threshold:type limit, track by_src, seconds 3600, count 1; classtype:misc-attack; flowbits:set,ET.Evil; flowbits:set,ET.DROPIP; sid:2400018; rev:4816; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag Dshield, signature_severity Minor, created_at 2010_12_30, updated_at 2026_08_31;)

Metadata

affected productAny
attack targetAny
deploymentPerimeter
tagDshield
signature severityMinor
created at2010_12_30
updated at2026_08_31

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!