# IP Intelligence Briefing: 108.62.60.167/32
Classification: Moderate Risk | Date: 2026-06-24
Analyst: IPDebrief Intelligence Team
Status: Requires Monitoring
---
## Executive Summary
IP address 108.62.60.167 is assigned to LeaseWeb USA, Inc. Seattle (ASN 396190). The IP carries a moderate risk score of 50 with no active threat indicators. However, the IP resides within a high-abuse subnet (108.62.60.0/24) with 73.8% abuse density. No services are currently running on this address, and no threat indicators are present.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **Organization** | LeaseWeb USA, Inc. Seattle |
| **ASN** | 396190 |
| **Location** | Seattle, WA, US |
| **Risk Score** | 50 (Moderate) |
| **Network Role** | Firewalled / No Services |
| **DNS Status** | No PTR records, no forward resolution |
| **Open Ports** | None detected |
| **DNSSEC Valid** | Yes |
---
## Threat Assessment
Current Indicators:
- No blacklist listings
- No known campaigns
- No Tor exit node activity
- No known attacker classification
- Not identified as spam source
Control Plane:
- BGP Prefix: 108.62.56.0/21
- Route Stability: Unstable (0 route changes in 30 days)
- RPKI State: Not validated
- DNSBL Listed: 2 of 8 total lists
---
## Neighborhood Analysis
The IP belongs to subnet 108.62.60.0/24, which exhibits concerning characteristics:
- Abuse Density: 73.8% (high_abuse classification)
- Active Siblings: 172 of 256 total IPs
- Threat Siblings: 189 identified threat neighbors
- Inherited Risk: 29
The neighborhood shows elevated abuse activity, though the specific IP (108.62.60.167) does not exhibit malicious behavior.
---
## Historical Observations
Signal Count: 24 observations recorded
- Recent operator score: 0.2174 (Minimal)
- Geo validation: ICMP blocked (unable to validate distance)
- Threat persistence: 0 days
- Persistent malicious activity: No
The IP has maintained stable characteristics with no significant escalation in risk over the observation period.
---
## Recommended Actions
Based on the moderate risk score (50) and high-abuse subnet context, the following measures are recommended:
Immediate Actions
- Block at perimeter firewall (iptables, nftables, pfSense)
- Deny at application layer (nginx, Apache)
- Block at WAF level (Cloudflare, AWS WAF)
Firewall Rules
```bash
# iptables
iptables -A INPUT -s 108.62.60.167 -j DROP
# nftables
nft add rule inet filter input ip saddr 108.62.60.167 drop
# Cloudflare WAF
{"description": "Block 108.62.60.167 β IPDebrief risk score 50", "action": "block"}
```
Monitoring Recommendations
- Monitor subnet 108.62.60.0/24 for lateral threats
- Implement geo-blocking for Seattle region if not already in place
- Review for any recent service openings on this IP
---
## Intelligence Notes
While the IP itself shows no active malicious indicators, the high abuse density of its /24 subnet warrants defensive posturing. The moderate risk score (50) combined with the provider classification suggests this may be a legitimate infrastructure IP that is being leveraged by malicious actors in the broader subnet. No immediate compromise indicators were identified for this specific address.
---
Disclaimer: All intelligence data is sourced from IPDebrief automated analysis. Verification with internal threat detection systems is recommended before taking remediation actions.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LeaseWeb USA, Inc. Seattle |
| ASN | AS396190 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:57 UTC |
| Last Seen | 2026-06-26 18:11:56 UTC |
| Profile Built | 2026-06-24 21:30:25 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.