Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Sapp Bros

Group: Worldleaks

Discovered by ransomware.live: 2025-09-23

Estimated attack date: 2025-09-23

Country: US

Description:

[AI generated] Sapp Bros is an American company with a network of service centers and travel centers across the midwest. Founded in 1971, the company started as a single service station. Now, it operates 17 full-service travel centers that feature amenities like restaurants, merchandise, fuel products, and truck service centers. They also offer petroleum and propane services.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 20

Third Party Employee Credentials: 0


External Attack Surface: 3


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse tucows.com
MX Records
  • d101795a.ess.barracudanetworks.com.
  • d101795b.ess.barracudanetworks.com.
TXT Records
  • amazon-business-verification=301395a06bbb18a2a182d08151e6b59dbab212e591116aa1a3f643b284876a80
  • apple-domain-verification=llZgr7Xw7SFRw4mq
  • bda9d35f9c11e5a221b9c01ff50d5bef
  • mgverify=9ddd26c25ad7e8022af3e1c06fd7a62958c7424ada2482135a24a8599a1fc5e8
  • v=spf1 include:spf.ess.barracudanetworks.com include:_spf.salesforce.com include:spf.protection.outlook.com include:mailgun.org include:_spf.activedemand.com ip4:98.142.83.226/27 ip4:74.112.208.34 ip4:66.37.239.138/30 ip4:128.136.148.244 ~all
  • MS=6C8A1C68FD379CC998D7BD92CF684E915750BB32
  • ZOOM_verify_6K1KpfSG71BlPvW8tuX8gt
  • _wvlzfbim18eiq88vwdnkf6mrp7lzu7g
Cloud / SaaS Services Detected
Apple Salesforce Mailgun Zoom

Leak Screenshot:

Leak Screenshot