
Summary
This rule flags inbound email whose chain of IPs in the Received headers traverses a netblock listed on Spamhaus DROP (Don’t Route Or Peer). The DROP feeds (v4 and v6) identify hijacked or criminally leased IP space that Spamhaus recommends blocking outright. The rule is attribution-based to Spamhaus and uses automatic feed refreshes, preserving the copyright, list date, and terms URL from Spamhaus per their terms. Detection relies on header analysis to extract the IP path from Received headers and sender analysis to correlate trust/red flags from the sending source. When any hop falls within a DROP netblock, the message is flagged as high severity due to association with compromised infrastructure used for malware distribution, phishing, or BEC. The rule is categorized under Attack surface reduction and covers detection methods focusing on header and sender information. Attack types include Malware/Ransomware, Credential Phishing, and BEC/Fraud, with TTPs of Evasion and Social engineering. This rule helps network boundaries identify and potentially quarantine or escalate suspicious mail at the earliest stage by leveraging widely trusted external reputation data. The source rules are stored at the file path indicated and reference Spamhaus drops via the provided feed URLs. Note that legitimate mail can sometimes appear to traverse DROP blocks due to misconfigurations or forwarding architectures, so findings should be correlated with sender reputation and organizational mail flow policies. The rule is designed for network-level analysis of inbound mail and is maintained with automatic updates from Spamhaus to maintain current coverage of IP space deemed untrustworthy.
Categories
- Network
Data Sources
- Network Traffic
Created: 2026-08-14