
Summary
Detects inbound email where the Received-header IP path transits IP space announced by ASNs on Spamhaus ASN-DROP. This is Spamhaus attribution (not an internal Sublime observation). ASN ranges are resolved from the listed ASNs and refreshed automatically; the Spamhaus copyright, list date, and terms URL are preserved in the rule source. Detection uses header analysis (Received headers) and sender analysis to determine provenance. Classified as high severity under attack surface reduction, it targets threats tied to malware/ransomware, credential phishing, and BEC/fraud by identifying mail routes through malicious networks. The rule relies on real-time ASN-DROP data and attribution rather than local observations, with automatic range refresh.
Categories
- Network
- Application
Data Sources
- Network Traffic
Created: 2026-08-14