AthenaSecurity: spamming
AthenaSecurity.net, a domain owned by Lisle Technology Partners, LLC, of Lombard, IL, is spamming. The address involved has not been given to anybody for inclusion on a mailing list, and it doesn’t appear in any web resources either. The mail doesn’t contain any hints as to where the address was obtained, why, and how. I wonder if this qualifies as mainsleaze or just the garden variety of spam.
Spamming IP: 168.93.77.75
Spam headers:
From jed@athenasecurity.net Wed Dec 21 01:03:26 2011 Return-Path: <jed@athenasecurity.net> Received: from vega.athenasecurity.net (vega.athenasecurity.net [168.93.77.75]) by mail.atrotossavainen.fi (Postfix) with ESMTP id 1EB91794CDB for <x>; Wed, 21 Dec 2011 01:03:25 +0200 (EET) Received: by vega.athenasecurity.net for <x>; Tue, 20 Dec 2011 20:55:18 GMT Message-ID: <20111220145424-1.1.x@openemm.invalid> Date: Tue, 20 Dec 2011 20:55:18 GMT From: AthenaSecurity <jed@athenasecurity.net> To: <x> Subject: Achieving Firewall Nirvana X-Mailer: OpenEMM V5.5.1 MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="-==AGNITASOUTER164240059B2900022C==" Content-Length: 10413 Lines: 259
Human-readable spam content:
Advice any firewall guru could use
How do I optimize rules for performance?
How do I report compliance?
What’s blocking this service?
Is this change safe to make?
Where is the best place to make it?Has it been a while since you’ve tested Athena?
Download the free trial:
http://vega.athenasecurity.net/r.html?uid=xHere are some updates you might have missed:
Athena FirePAC can:– Consider the impact of rules on multiple devices and on multiple
routing paths
– Leverage device logs for near real-time scheduled analysis of actual
rule usage
– Gather documentation for use in rule life cycle management
– Model and simulate changes to assess risk and compliance pre-
deploymentRequest a technical briefing:
http://vega.athenasecurity.net/r.html?uid=xAbout Athena
Athena offers solutions for network and security engineers to improve
the efficiency, security and manageability of layer 3 network devices.For more information see www.athenasecurity.net
If you would prefer not to receive notices and announcements from us in
the future please use the following link to unsubscribe:
http://vega.athenasecurity.net/r.html?uid=x
This spam was sent from a server with rDNS that indicates it belongs to athenasecurity.net. So, assuming that Athena Security is a legitimate company, this appears to meet our definition of mainsleaze spam. Most mainsleaze spam is sent by an ESP, not the company itself, but I have blogged previously about mainsleaze spam that was sent by the company from its own IPs. Spam that a legitimate company sends from its own IPs to advertise its own products or services is definitely mainsleaze spam.
As i look back at those blogs, I noticed an interesting fact. At least half of the spam that I blogged about that came from ESPs elicited a response from the ESP that was followed by the spam stopping. In other cases, the ESP did not ever contact me, but ongoing spam from the customer that I reported stopped as well. In other words, the ESPs took effective action to stop the reported spam in more than half the cases.
This was not the case with most of the direct mainsleaze spam. In none of those cases did the company contact me, and in most of them the spam continued to be sent. It appears that companies that spam from their own IPs are less willing and/or able to stop the spam than companies that spam via an ESP, or perhaps just aren’t paying attention to the blog. In my experience, spam complaints sent to Postmaster or Abuse role accounts at most companies either bounces (“No such address”) or disappears into a bitbucket, but perhaps I should send complaints anyway….
I went through this with Athena almost 2 years ago. They double spammed a very new corporate email address. I called them and they claimed it was due to over-zealous marketing initiative, and they promptly removed the address. That new email address was not known to too many people. At the time I recall thinking that they must somehow be leveraging Linked-In connections to gather their list.
The address they spammed isn’t even on LinkedIn. There’s a chance that it might be e-pended, but… an American company e-pending the officials of a Finnish company…? Just how unlikely is that…