Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2026-01-14
Est. attack date 2025-11-20
Country US
Data exfiltrated 512GB

Description:

[AI generated] JJ White is a multi-divisional construction company based in Philadelphia, Pennsylvania. It specializes in general, mechanical and industrial construction with additional services in HVAC maintenance and service, fire protection, and rigging projects. The company operates across the United States working with industries such as healthcare, pharmaceutical, petrochemical, and manufacturing.

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 0

Third Party Employee Credentials: 0


External Attack Surface: 1


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • mx2-us1.ppe-hosted.com.
  • mx1-us1.ppe-hosted.com.
TXT Records
  • 47ramto4ut34jroqjs9lqhi674
  • ppe-508760904113f8f388b75ff2dc5c9014b758d354
  • v=spf1 ip4:40.142.77.43 ip4:40.142.77.49 ip4:40.142.77.57 include:_spf-us.ppe-hosted.com a:dispatch-us.ppe-hosted.com include:spf.protection.outlook.com include:spf.myconnectwise.net ~all
  • mscid=blQpKAmIcsoYB1ETvsFSdO34SYNvWni3N+dRjIDjwhIkIAxEyiuM8Mde+z9J3CDtFrrkZPLZr/qz/2JyAqNWLA==
  • ca3-675d7a5221694cf782d2270d99dfddd9
  • MS=ms17684936
  • MS=E4FF12A482B08036327989B55442AFB2419C5E1D
  • google-site-verification=2MWHPpUSgTJ5WlUe1KzTvw_kxne1KZ6vHXmbBpUQ0f0
Cloud / SaaS Services Detected
Microsoft 365 Proofpoint Essentials

Leak Screenshot:

Leak Screenshot