Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo welcompanies.com

Group: Ransomhub

Discovered by ransomware.live: 2025-02-25

Estimated attack date: 2025-02-19

Country: US

Description:

[AI generated] Wel Companies is a renowned refrigerated freight and logistics company based in De Pere, Wisconsin. They specialize in providing temperature-controlled truckload and logistics services across North America. In operation since 1975, Wel Companies has established itself through customer-focused operations, advanced freight tracking systems, and a large fleet that prioritizes both sustainability and safety.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1

Third Party Employee Credentials: 10


External Attack Surface: 1



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • mx1-us1.ppe-hosted.com.
  • mx2-us1.ppe-hosted.com.
TXT Records
  • ppe-da3855363307dec9d744a7b174785ceeee7a3157
  • ppe-abc07ca7b13d260b2b94ebf9cd164b45d00f9e35
  • ppe-739e17a9fd2814beb9575afc6d2942acaec99ba8
  • ppe-ba307d9e538dbc375c609ca79b9ffd8b67e2ba5a
  • v=spf1 a:dispatch-us.ppe-hosted.com ip4:173.243.134.199 ip4:12.233.77.211 ip4:12.233.77.219 ip4:67.53.243.187 ip4:147.202.82.143 ip4:147.202.82.144 ip4:147.202.82.145 ip4:54.198.184.46 include:spf.protection.outlook.com ~all
  • apple-domain-verification=FeBAhCxEUiO0hJh8
  • ppe-4d93406586db8a1aef1e86df0d877104e2205048
Cloud / SaaS Services Detected
Apple Proofpoint Essentials

Leak Screenshot:

Leak Screenshot