# IP Intelligence Briefing: 108.62.58.178
## Executive Summary
IP 108.62.58.178 is a LeaseWeb USA infrastructure endpoint in Seattle, WA (ASN 396190). The IP presents moderate risk (score: 50) with no active threat indicators. The subnet demonstrates elevated abuse density (0.8633) with 221 threat siblings out of 256 total addresses. Current network classification indicates the IP is firewalled with no open services.
## Current Risk Profile
- Reputation: Moderate Risk (50/100)
- Classification: Firewalled / No Services
- DNSBL Status: Listed on 2 of 8 threat feeds
- Operator Score: 0.1304 (Minimal)
- Route Stability: False (routing instability detected)
- Known Threat Indicators: None
## Network Context
- Organization: LeaseWeb USA, Inc. Seattle
- BGP Prefix: 108.62.56.0/21
- Geolocation: Seattle, Washington, US
- Subnet Abuse Density: 0.8633 (High Abuse)
- Threat Siblings: 221 of 256 addresses (86% threat rate)
## Observed Behavior
- Services: No open ports; connection attempts fail with firewalled response
- DNS: No PTR records; forward resolution unconfirmed
- SSL/TLS: No certificates detected
- Campaign Activity: No known campaign associations
- Persistence: Non-persistently malicious (threat persistence: 0 days)
## Historical Activity
18 signal observations recorded between 2026-06-04 and 2026-06-09. Most recent observation (2026-06-09) shows continued moderate risk classification with no escalation. ICMP validation blocked across all probes.
## Neighborhood Intelligence
The /24 subnet (108.62.58.0/24) contains 256 sibling IPs with 134 currently active. Risk distribution shows 100 medium-risk neighbors, 0 high-risk, and 0 low-risk. The subnet exhibits inherited risk score of 34, indicating correlated abuse patterns across the address space.
## Recommended Actions
1. Monitor connections from this IP for anomalies; baseline behavior shows no active services
2. Block if unexpected inbound/outbound traffic detected (firewalled by design)
3. Correlate with subnet 108.62.58.0/24 for coordinated abuse indicators
4. Review 2 DNSBL listings to determine source of blacklisting
## Threat Assessment
Low immediate threat. The IP appears to be a legitimate cloud/hosting endpoint with no active malicious indicators. However, the high abuse density in the /24 subnet warrants continued monitoring. No firewall rules required unless specific traffic patterns deviate from established baseline.
---
*Report generated: 2026-06-09 | Data Source: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LeaseWeb USA, Inc. Seattle |
| ASN | AS396190 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:54 UTC |
| Last Seen | 2026-06-26 18:11:54 UTC |
| Profile Built | 2026-06-24 20:05:58 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.