# IP Intelligence Briefing: 108.62.61.157
## Executive Summary
IP 108.62.61.157 is a LeaseWeb USA infrastructure endpoint (ASN 396190) located in Seattle, Washington. The address presents a moderate risk profile (Score: 50) with no active services detected. However, the /24 subnet exhibits elevated abuse density (57%), warranting contextual assessment before remediation actions.
## Network Identity & Infrastructure
- ASN: 396190 (LeaseWeb USA, Inc. Seattle)
- Location: United States, Washington, Seattle (GeoConsensus: True)
- Control Plane: Not listed on DNSBL (2 lists across 8 total), DNSSEC valid
- Network Role: Firewalled / No Services
- Routing: BGP prefix 108.62.56.0/21, operator score 0.1304 (Minimal)
## Threat Profile
- Risk Score: 50 (Moderate Risk)
- Known Attack Indicators: None
- Spam Source: False
- Tor Exit Node: False
- Blacklist Count: 0
- Known Campaigns: None identified
- Threat Persistence: 0 days, not persistently malicious
## Neighborhood Context
The /24 subnet (108.62.61.0/24) shows significant activity:
- Abuse Density: 57% (classified as high_abuse)
- Active Siblings: 117 out of 256 total
- Threat Siblings: 146
- Inherited Risk: 22
- Sampled Neighbors: 100 IPs analyzed (99 medium risk, 1 low risk, 0 high risk)
This indicates the subnet contains substantial abuse activity, though this specific IP lacks direct threat indicators.
## Behavioral History
Observation history (20 signals, June 4-24, 2026) shows:
- Consistent "Minimal" operator scores
- Geovalidation challenges (ICMP blocked)
- Stable ownership with no changes recorded
- No emerging threat patterns detected
## Technical Characteristics
- DNS: No PTR hostnames, no forward resolution, no hosted domains
- Services: No open ports detected
- TLS/Certificates: None
- Email: No SPF/DMARC records
- Traceroute: 30 hops (Comcast, Lumen transit), 23 timed-out hops
## Recommended Actions
While the IP shows no direct threat indicators, the high-abuse neighborhood context suggests defensive posture consideration:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 108.62.61.157 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 108.62.61.157 drop` |
| nginx | `deny 108.62.61.157;` |
| pfSense | `108.62.61.157/32` |
| Cloudflare WAF | Block IP with expression `ip.src eq 108.62.61.157` |
| AWS WAF | Block IP 108.62.61.157/32 |
Note: These recommendations are probabilistic. Consider blocking based on observed traffic patterns and organizational policy.
## Intelligence Assessment
The IP presents minimal direct threat indicators but operates within a high-abuse subnet context. The absence of services and lack of blacklist presence suggests this may be legitimate infrastructure. Recommend monitoring rather than immediate blocking unless observed malicious traffic correlates with this address.
Classification: Moderate Risk / Neighborhood Context Required
Priority: Standard Monitoring
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LeaseWeb USA, Inc. Seattle |
| ASN | AS396190 |
| Network Name | β |
| CIDR Block | 108.62.56.0/21 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 3 |
| routing | 32% | 2 | 3 |
| services | 20% | 2 | 2 |
| ownership | 28% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 26% | 12 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:58 UTC |
| Last Seen | 2026-06-26 18:11:57 UTC |
| Profile Built | 2026-06-26 23:58:59 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 28 |
Full dossier details are available via our API.