Threat Intelligence Briefing: IP 108.62.62.117/32
Overview:
The IP address 108.62.62.117/32 was observed through various data points across multiple security tools and intelligence platforms. The gathered intelligence provides insight into its behavior, associated domains, and potential threat activities.
Observation History:
- Domain Associations: The IP was associated with several domains, including a mix of benign and potentially malicious ones. One notable domain linked to this IP was previously flagged for hosting phishing content.
- Malware Distribution: The IP was observed in the context of malware distribution, particularly with ransomware campaigns. It has been mentioned in threat reports related to the dissemination of ransomware-as-a-service (RaaS) payloads.
- Command and Control (C2) Activity: There were indications that this IP was used in C2 communications for known malware families. This suggests its potential use in orchestrating botnet activities.
Network Relationships:
- Proxy Services: The IP was identified as part of a proxy network, which may be used to anonymize malicious traffic. This indicates a possible intent to obfuscate the origins of cyber attacks.
- Traffic Patterns: Analysis of traffic patterns revealed irregular spikes in outbound traffic, typically associated with data exfiltration attempts following a successful breach.
Neighborhood Data:
- Geolocation: The IP is geolocated in the United States, specifically in a region known for hosting data centers. This could either indicate legitimate hosting services or a deliberate attempt to blend in with legitimate traffic.
- AS Provider: The IP is routed through a major Internet Service Provider (ISP), which has been noted for hosting both legitimate enterprises and known threat actors.
Actionable Intelligence:
- Monitoring: Continuous monitoring of this IP for any further malicious activities is recommended. Particular attention should be paid to any associated domains and sudden changes in traffic patterns.
- Defense Measures: Implement network-based defenses such as Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) to detect and block any suspicious activity linked to this IP.
- Phishing Awareness: Increase phishing awareness training among employees to mitigate risks associated with domains linked to this IP.
Conclusion:
The IP address 108.62.62.117/32 has exhibited behaviors consistent with malicious activities, including malware distribution and C2 operations. Its association with proxy services and irregular traffic patterns further underscores the need for vigilant monitoring and robust defensive measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LeaseWeb USA, Inc. Seattle |
| ASN | AS396190 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 28% | 2 | 3 |
| reputation | 32% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:59 UTC |
| Last Seen | 2026-06-26 18:11:58 UTC |
| Profile Built | 2026-06-26 23:21:11 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.