Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo JJ White

Group: Payoutsking

Discovered by ransomware.live: 2026-01-14

Estimated attack date: 2025-11-20

Country: US

Data exfiltrated: 512GB

Description:

[AI generated] JJ White is a multi-divisional construction company based in Philadelphia, Pennsylvania. It specializes in general, mechanical and industrial construction with additional services in HVAC maintenance and service, fire protection, and rigging projects. The company operates across the United States working with industries such as healthcare, pharmaceutical, petrochemical, and manufacturing.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 0

Third Party Employee Credentials: 0


External Attack Surface: 1



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • mx1-us1.ppe-hosted.com.
  • mx2-us1.ppe-hosted.com.
TXT Records
  • MS=ms17684936
  • google-site-verification=2MWHPpUSgTJ5WlUe1KzTvw_kxne1KZ6vHXmbBpUQ0f0
  • mscid=blQpKAmIcsoYB1ETvsFSdO34SYNvWni3N+dRjIDjwhIkIAxEyiuM8Mde+z9J3CDtFrrkZPLZr/qz/2JyAqNWLA==
  • 47ramto4ut34jroqjs9lqhi674
  • ppe-508760904113f8f388b75ff2dc5c9014b758d354
  • ca3-675d7a5221694cf782d2270d99dfddd9
  • MS=E4FF12A482B08036327989B55442AFB2419C5E1D
  • v=spf1 ip4:40.142.77.43 ip4:40.142.77.49 ip4:40.142.77.57 include:_spf-us.ppe-hosted.com a:dispatch-us.ppe-hosted.com include:spf.protection.outlook.com include:spf.myconnectwise.net ~all
Cloud / SaaS Services Detected
Microsoft 365 Proofpoint Essentials

Leak Screenshot:

Leak Screenshot