# IP Intelligence Briefing: 108.62.62.185/32
## Executive Summary
IP address 108.62.62.185 is classified as Moderate Risk with a risk score of 50. The address is owned by LeaseWeb USA, Inc. Seattle (ASN 396190) and is geolocated to Seattle, WA. The IP is currently in a firewalled state with no active services, but the associated /24 subnet shows elevated abuse density.
## Ownership and Infrastructure
| Attribute | Value |
|---|---|
| **ASN** | 396190 |
| **Organization** | LeaseWeb USA, Inc. Seattle |
| **Network Name** | 108-62-56-0 |
| **RIR** | ARIN |
| **BGP Prefix** | 108.62.56.0/21 |
| **Geolocation** | Seattle, WA, US |
## Threat Indicators
- Risk Score: 50 (Moderate)
- DNSBL Listed: 2 of 8 total lists
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Threat Feeds: None populated
## Network Services Assessment
- Open Ports: None detected
- HTTP/HTTPS: No services listening
- TLS Certificates: None
- DNS Records: No PTR or forward resolution
- Service Purpose: Firewalled / No Services
## Subnet Neighborhood Analysis (108.62.62.0/24)
- Total Siblings: 256 IPs
- Active Siblings: 141
- Threat Siblings: 143
- Abuse Density: 0.5586 (High Abuse Classification)
- Risk Distribution: 9 High, 91 Medium, 0 Low
The IP operates within a subnet showing significant abuse activity. Of 100 sampled neighbors, 9 were classified as high-risk. The subnet's overall abuse density suggests concentrated malicious activity from adjacent addresses.
## Historical Observation Trend
Analysis of 17 observations spanning June 17β19, 2026 indicates stable threat posture with no escalation:
- Consistent Risk Level: All observations returned "Minimal" risk designation (0.15 raw score)
- Operator Score: 0.1304 across all observations
- Threat Persistence: Zero persistence days
- Ownership Changes: None recorded
## Recommended Security Actions
Based on the IP's risk profile and neighborhood context, the following blocking rules are recommended:
Firewall Rules:
- `iptables -A INPUT -s 108.62.62.185 -j DROP`
- `nft add rule inet filter input ip saddr 108.62.62.185 drop`
- `nginx: deny 108.62.62.185;`
- `pfSense: 108.62.62.185/32`
- Cloudflare WAF: Block IP 108.62.62.185 β IPDebrief risk score 50
- AWS WAF: Add 108.62.62.185/32 to blocked addresses
## Intelligence Assessment
The IP 108.62.62.185 presents moderate risk primarily due to its neighborhood context rather than individual threat indicators. The absence of open services and clean DNS footprint suggest this is an infrastructure address within a high-abuse subnet. The consistent "Minimal" risk signals over multiple observations indicate this IP has not been actively exploited as a compromised host.
SOC Action Priority: Monitor β Block at perimeter firewall level if traffic is observed. The subnet's high abuse density warrants consideration of blocking the entire /24 range if operational impact permits.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LeaseWeb USA, Inc. Seattle |
| ASN | AS396190 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 20% | 2 | 2 |
| ownership | 28% | 2 | 3 |
| reputation | 32% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:59 UTC |
| Last Seen | 2026-06-26 18:11:58 UTC |
| Profile Built | 2026-06-26 23:08:29 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 21 |
Full dossier details are available via our API.