ET DROP Spamhaus DROP Listed Traffic Inbound group 47
Sourceet/open
Filedrop.rules
CreatedDecember 30, 2010
UpdatedSeptember 1, 2026
Classificationmisc-attack
alert ip [196.251.98.0/23,196.251.100.0/24,196.251.102.0/24,196.251.107.0/24,196.251.112.0/22,196.251.116.0/23,196.251.118.0/24,196.251.121.0/24,196.251.122.0/24,197.11.156.0/24,197.231.248.0/22,197.234.221.0/24,198.13.64.0/21,198.13.72.0/23,198.17.78.0/24,198.17.197.0/24,198.20.16.0/20,198.37.0.0/22,198.41.4.0/22,198.45.32.0/20] any -> $HOME_NET any (msg:"ET DROP Spamhaus DROP Listed Traffic Inbound group 47"; reference:url,www.spamhaus.org/drop/drop.txt ; threshold:type limit, track by_src, seconds 3600, count 1 ; classtype:misc-attack; flowbits:set,ET.Evil ; flowbits:set,ET.DROPIP ; sid:2400046; rev:4817; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag Dshield, signature_severity Minor, created_at 2010_12_30, updated_at 2026_09_01;)
References
Metadata
affected productAny
attack targetAny
deploymentPerimeter
tagDshield
signature severityMinor
created at2010_12_30
updated at2026_09_01
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!