# IP Intelligence Briefing: 108.62.62.23/32
## Executive Summary
IP 108.62.62.23 presents a MODERATE RISK profile with a risk score of 50. The address is associated with LeaseWeb USA, Inc. Seattle (ASN: 396190) and is geolocated to Seattle, WA. While no direct threat indicators were identified, the IP resides in a high-abuse-density subnet (108.62.62.0/24) with 145 threat siblings detected, warranting defensive consideration.
## Risk Profile
| Metric | Value |
|---|---|
| Risk Score | 50 (Moderate) |
| Provider Score | 0 |
| Authority Score | 0 |
| DNSBL Listed | 2/8 lists |
| Classification | High Abuse Subnet |
| Reputation | Moderate Risk |
## Technical Details
- Organization: LeaseWeb USA, Inc. Seattle
- ASN: 396190
- Geolocation: United States, Washington, Seattle
- DNS: 108.62.62.23.rdns.1ue.com
- Network Role: Firewalled / No Services (no open ports detected)
- Control Plane: Route stable (0 changes in 30 days), RPKI valid, DNSSEC valid
- ISP Class: Basic (Operator Score: 0.3913)
## Neighborhood Analysis
The IP is part of subnet 108.62.62.0/24 with concerning characteristics:
- Abuse Density: 0.5664 (high_abuse classification)
- Total Siblings: 256
- Active Siblings: 143
- Threat Siblings: 145
- Inherited Risk: 22
Neighboring IPs show mixed risk distribution (8 high, 91 medium, 1 low), indicating the subnet warrants monitoring rather than blanket blocking.
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaigns: None detected
- Scans/Probes: No recent activity observed
## Historical Observations
Analysis of 28 observations reveals consistent behavior over time:
- Recent operator scores: 0.3913 (Basic) and 0.2174 (Minimal)
- No significant risk escalation detected
- Ownership and threat persistence stable (0 changes)
- Threat observation count: 1
## Recommended Actions
Given the moderate risk score and high-abuse subnet context:
1. Firewall Rules (recommended):
- `iptables`: `iptables -A INPUT -s 108.62.62.23 -j DROP`
- `nftables`: `nft add rule inet filter input ip saddr 108.62.62.23 drop`
- `nginx`: `deny 108.62.62.23;`
- `Cloudflare WAF`: Block IP with expression `ip.src eq 108.62.62.23`
- `AWS WAF`: Add `108.62.62.23/32` to block list
2. Subnet-level Monitoring: Consider monitoring the 108.62.62.0/24 subnet due to high abuse density (0.5664) and 145 threat siblings.
3. Investigation Priority: MEDIUM - Monitor for traffic patterns rather than immediate blocking unless additional context is provided.
## SOC Analyst Notes
This IP presents a moderate threat profile with no direct malicious indicators. The primary concern is the high-abuse-density subnet context. Recommend implementing the provided firewall rules while correlating with internal threat data. The IP shows stable routing and no recent behavioral changes, suggesting established rather than ephemeral malicious activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LeaseWeb USA, Inc. Seattle |
| ASN | AS396190 |
| Network Name | β |
| CIDR Block | 108.62.56.0/21 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 108.62.62.23.rdns.1ue.com |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 108.62.62.23.rdns.1ue.com |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 20% | 2 | 3 |
| services | 20% | 2 | 3 |
| ownership | 22% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 24% | 12 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:59 UTC |
| Last Seen | 2026-06-26 18:11:58 UTC |
| Profile Built | 2026-06-26 23:37:14 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 30 |
Full dossier details are available via our API.