IPDebrief

108.62.57.41

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# Threat Intelligence Briefing: 108.62.57.41

Classification: Moderate Risk / Infrastructure Provider

Report Date: Current Analysis

IP Address: 108.62.57.41/32

---

## Executive Summary

The IP address 108.62.57.41 belongs to LeaseWeb USA, Inc. Seattle (ASN 396190) and is classified as moderate risk (risk score: 40). The address resides within a high-abuse density subnet (108.62.57.41/24) with 190 threat siblings identified among 256 total addresses. No open services or active threat indicators were detected on this specific IP, but the neighborhood context indicates elevated regional risk.

---

## Ownership and Network Context

Provider: LeaseWeb USA, Inc. Seattle

ASN: 396190

Geolocation: Seattle, WA, US (US, WA)

BGP Prefix: 108.62.56.0/21

Network Classification: Provider infrastructure, firewalled/no services

The IP is owned by a known hosting provider. No service banners or open ports were observed during scanning. The address resolves to geolocation coordinates approximately 39.83°N, -98.58°W with an accuracy radius of 2,500 km.

---

## Threat Assessment

Current Risk Score: 40 (Moderate Risk)

Abuse Confidence: Data insufficient for precise scoring

Blacklist Status: 0 blacklist listings (current profile)

Tor/Proxy: Not identified as Tor exit node, proxy, or VPN

Known Attacker: No association with known attacker IP databases

Spam Source: No spam source indicators

Threat Indicators: None currently active

Campaign Associations: None identified

Cert Matches: 0

---

## Neighborhood Analysis

Subnet: 108.62.57.41/24

Abuse Density: 0.7422 (High Abuse Classification)

Total Siblings: 256

Active Siblings: 156

Threat Siblings: 190

The /24 subnet exhibits high abuse density with 74% of active IPs flagged as threats. Risk distribution across neighbors shows 100 medium-risk addresses, 0 high-risk, and 0 low-risk. All neighboring IPs returned risk score 50 with authority score 50.

---

## Historical Observations

Total Observations: 18 signals collected

Key Historical Events:

Recent signal activity (2026-06-24) shows minimal threat indicators with operator score of 0. No persistent malicious behavior detected over the observation period.

---

## Relationship Graph

Total Relationships: 29

Network Relationships: All 29 relationships point to network 108.62.56.0

Hostname Relationships: None

Organization Relationships: None

Certificate Relationships: None

The IP has no associated hostnames, organizations, or SSL certificates in the relationship database.

---

## Recommended Actions

Status: No immediate action required based on current risk profile

Monitoring Recommendations:

Firewall Rules: No specific firewall rules generated due to low individual IP risk. Consider subnet-level blocking policies given the high abuse density environment.

---

## Conclusion

IP 108.62.57.41 is a provider infrastructure address with moderate risk classification. While the individual IP shows no active threats or open services, the subnet exhibits high abuse density. SOC teams should monitor for any service activation or behavioral changes, as the neighborhood context indicates this IP may be used for legitimate hosting services within a high-risk environment. The historical DNS blacklist listing on 2026-06-04 suggests past abuse activity that may be resolved or attributed to neighboring IPs.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionWA
CitySeattle
Timezoneβ€”
Latitude47.61
Longitude-122.33

🏒 Ownership & Registration

OrganizationLeaseWeb USA, Inc. Seattle
ASNAS396190
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
36%
24
routing
8%
11
services
15%
22
ownership
20%
23
reputation
22%
12
geolocation
24%
23
Overall21%1015
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:04:53 UTC
Last Seen2026-06-26 18:11:52 UTC
Profile Built2026-06-25 01:01:03 UTC
Data FreshnessLive
Signal Types18
Total Observations22
πŸ” 18 signal types Β· 22 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.