IPDebrief

108.62.57.82

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 108.62.57.82/32

Date: June 2026

Classification: Moderate Risk (Score: 65/100)

Prepared For: SOC Operations Team

---

## Executive Summary

IP address 108.62.57.82 is associated with LeaseWeb USA, Inc. Seattle (ASN 396190) and presents moderate risk. The IP resolves to domain 3e.vc with SPF configuration but lacks DMARC validation. While the IP itself shows no active open ports, the /24 subnet exhibits high abuse density (0.7656), indicating a potentially compromised hosting environment.

---

## Infrastructure Profile

AttributeValue
**Risk Score**65/100 (Moderate)
**Provider**LeaseWeb USA, Inc. Seattle
**ASN**396190
**Geolocation**Seattle, WA, US
**CIDR Block**108.62.56.0/21
**Network Role**Firewalled / No Services

DNS Configuration:

---

## Threat Indicators

Control Plane Analysis:

---

## Neighborhood Analysis

The /24 subnet (108.62.57.0/24) demonstrates concerning abuse characteristics:

MetricValue
**Abuse Density**0.7656 (High)
**Classification**High Abuse
**Active Siblings**156 of 256 total
**Threat Siblings**196
**IP Risk Distribution**99 Medium, 1 Low

The elevated abuse density suggests this IP resides within a compromised or poorly monitored hosting environment.

---

## Historical Observations

Analysis of 28 observations reveals:

---

## Recommended Actions

Immediate Mitigation

1. Block at Egress/Ingress: The IP presents elevated risk and should be blocked unless business-justified traffic exists.

2. Monitor Subnet: Given high neighborhood abuse density, implement logging and monitoring for the entire 108.62.57.0/24 subnet.

Firewall Implementation

```bash

# iptables

iptables -A INPUT -s 108.62.57.82 -j DROP

# nftables

nft add rule inet filter input ip saddr 108.62.57.82 drop

# Cloudflare WAF

{

"description": "Block 108.62.57.82 β€” IPDebrief risk score 65",

"action": "block",

"filter": {"expression": "ip.src eq 108.62.57.82"}

}

# AWS WAF

{

"Addresses": ["108.62.57.82/32"],

"Description": "IPDebrief risk 65"

}

```

---

## Intelligence Assessment

This IP requires blocking due to its moderate risk profile combined with high-abuse neighborhood context. The absence of active services reduces immediate threat potential, but the subnet-level risk warrants defensive posture. Monitor for any changes in service activity or threat indicators, and consider broader subnet-level filtering if false positives do not impact legitimate traffic.

---

*Report generated using IPDebrief Intelligence Platform. Recommendations should be validated against operational requirements before implementation.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionWA
CitySeattle
Timezoneβ€”
Latitude47.61
Longitude-122.33

🏒 Ownership & Registration

OrganizationLeaseWeb USA, Inc. Seattle
ASNAS396190
Network Nameβ€”
CIDR Block108.62.56.0/21
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR108.62.57.82.rdns.3e.vc
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames108.62.57.82.rdns.3e.vc

πŸ” DNS Hygiene

Hygiene Score60% (Good)
SPF1/2 domains
DMARC0/2 domains
FCrDNSNot verified
DNSSECValid
CAAPresent
Domains Checked2 domains

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
33%
24
routing
24%
23
services
15%
22
ownership
27%
34
reputation
31%
13
geolocation
24%
23
Overall26%1219
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:04:53 UTC
Last Seen2026-06-26 18:11:52 UTC
Profile Built2026-06-24 19:07:00 UTC
Data FreshnessLive
Signal Types28
Total Observations32
πŸ” 28 signal types Β· 32 observations collected
This report is generated from 28+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.