Your IP: 216.73.216.123
π€ Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.
Threat Intelligence Briefing for IP Address 108.62.59.170/32
Observation History:
- The IP address 108.62.59.170/32 was observed engaging in network activities primarily associated with web traffic. The traffic patterns indicate a consistent flow of both inbound and outbound connections. Historical data shows periods of increased activity during typical business hours, suggesting routine operations or service usage.
Profile:
- The IP address is registered to a telecommunications company known for providing cloud and digital services. The services include hosting, content delivery networks (CDN), and internet connectivity solutions. This profile suggests a legitimate use case for the IP address, primarily serving customer and partner networks.
Relationships:
- The IP address is part of a network of addresses associated with the same telecommunications entity. It frequently communicates with other IPs within the same organization, indicating internal or related service operations. There are no direct associations with known malicious IP addresses or domains, based on the available data.
Neighborhood Data:
- The IP address resides within a subnet that includes several other IPs belonging to the same organization. The network neighborhood is characterized by similar traffic patterns, primarily focused on web services and data exchange. There is no evidence of suspicious or anomalous activity within the immediate network vicinity.
Actionable Insights:
- Given the legitimate nature of the IP address and its association with a reputable telecommunications provider, the traffic observed should be considered benign under normal circumstances. However, SOC teams should remain vigilant for any deviations from established traffic patterns, such as unusual spikes in data transfer or connections to unexpected external IPs, which could indicate a compromise or misuse of the service.
- Continuous monitoring of this IP and its associated traffic is recommended to ensure ongoing compliance with security policies and to detect any potential threats early. Implementing network segmentation and applying strict access controls can further mitigate risks associated with legitimate services being exploited.
This briefing provides a comprehensive overview based on the observed data, enabling SOC analysts to make informed decisions regarding the management and monitoring of network traffic related to IP 108.62.59.170/32.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LeaseWeb USA, Inc. Seattle |
| ASN | AS396190 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
No certificate
Issued by β
N/A
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 36% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 25% | 10 | 16 |
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:56 UTC |
| Last Seen | 2026-06-26 18:11:55 UTC |
| Profile Built | 2026-06-25 00:32:47 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
π 18 signal types Β· 20 observations collected
This report is generated from 18+ independent intelligence signals including
ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds,
behavioral fingerprinting, and more.
Full dossier details are available via our API.
Full dossier details are available via our API.
βΉοΈ About This Report
All data shown is publicly available network metadata β IP addresses do not reliably identify individuals.
Assessments are probabilistic and should not be used as sole basis for access control decisions.
To report an issue or request data review, contact admin@ipdebrief.com.