# IP Intelligence Briefing: 108.62.60.129/32
## Executive Summary
The target IP 108.62.60.129 is classified as a Moderate Risk endpoint (risk score: 50) hosted by LeaseWeb USA, Inc. Seattle (ASN 396190). The IP resides within a high-abuse subnet (108.62.60.0/24) with 73.83% abuse density and 189 of 256 sibling IPs flagged as threats. Current network classification shows the endpoint is firewalled with no active services.
## Risk Profile
| Metric | Value |
|---|---|
| Risk Score | 50 (Moderate) |
| Abuse Confidence | DNSBL listed on 2 of 8 threat lists |
| Subnet Classification | High Abuse (108.62.60.0/24) |
| Inherited Risk Score | 29 |
| Provider Score | 0 |
| Authority Score | 0 |
## Ownership & Geolocation
- Organization: LeaseWeb USA, Inc. Seattle
- ASN: 396190
- CIDR Block: 108.62.56.0/21 (BGP prefix)
- Location: United States, Washington (Seattle)
- Geolocation Accuracy: Radius 2,500km, consensus validated across multiple sources
- Registration: ARIN RIR
## Network Services & DNS
- Open Ports: None detected
- DNS Records: No PTR records, no forward resolution
- Email Authentication: No SPF/DMARC records detected
- HTTP Services: No active web services
- TLS Certificates: None observed
## Threat Intelligence
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
- Campaign Correlation: No matching campaigns detected
- Threat Feeds: Multiple pulse indicators from AlienVault OTX (50+ pulses)
- Recent Activity: 23 signal observations recorded, with threat indicators observed as recently as June 2026
- Route Stability: Unstable routing (isRouteStable: false), though no route changes in last 30 days
## Neighborhood Analysis
The /24 subnet (108.62.60.0/24) shows concentrated abuse activity:
- Abuse Density: 73.83%
- Active Siblings: 172 of 256 IPs
- Threat Siblings: 189 IPs flagged
- Neighbor Risk Distribution: 99 medium-risk, 1 low-risk, 0 high-risk neighbors
- Risk Correlation: 100 neighboring IPs analyzed, most with risk score 50
## Relationship Graph
- Total Relationships: 116
- Primary Connections: Same network blocks (108.62.56.0/21)
- Entity Types: Network associations dominate relationship graph
## Historical Trends
23 observations tracked with consistent threat indicators:
- June 2026: Multiple threat pulses from AlienVault OTX
- June 2026: Operator score 0.2174 (minimal)
- June 2026: Subnet abuse density confirmed at 73.83%
- June 2026: Geographic validation challenges (ICMP blocked)
- No persistent malicious behavior flagged despite subnet-level abuse
## Recommended Actions
1. Monitor Traffic: Implement traffic analysis for this subnet (108.62.60.0/24) given high abuse density
2. DNSBL Verification: Confirm listing status across remaining 6 DNSBL sources
3. Service Monitoring: Continue passive monitoring for service emergence (currently firewalled)
4. Reputation Assessment: Evaluate if IP-specific reputation warrants additional blocking measures
5. Geolocation Validation: Consider additional probes to validate Seattle location claim
## Intelligence Notes
This IP represents a low-to-moderate risk endpoint within a heavily abused hosting network. The moderate risk score (50) combined with the high-abuse subnet context warrants defensive monitoring but does not indicate immediate threat. The lack of open services suggests this may be a residential or enterprise endpoint rather than a hosting infrastructure asset. Threat persistence is not flagged, indicating transient rather than persistent malicious activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LeaseWeb USA, Inc. Seattle |
| ASN | AS396190 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 22% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:57 UTC |
| Last Seen | 2026-06-26 18:11:56 UTC |
| Profile Built | 2026-06-24 21:24:29 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 26 |
Full dossier details are available via our API.