## Intelligence Briefing: IP 108.62.56.167/32
Classification: Moderate Risk | Risk Score: 50 | Status: Active
Executive Summary
IP address 108.62.56.167 belongs to LeaseWeb USA, Inc. Seattle (ASN 396190) and is located in Tukwila, Washington, US. The IP exhibits moderate risk characteristics with no specific threat indicators but operates within a high-abuse-density subnet environment. The address is currently firewalled with no active services.
Ownership and Infrastructure
- Organization: LeaseWeb USA, Inc. Seattle
- ASN: 396190
- Location: US, WA, Tukwila
- BGP Prefix: 108.62.56.0/21
- Network Status: Route unstable (isRouteStable: false)
- Infrastructure Type: Unknown
Network Role Assessment
The IP shows no open ports and no detected services. DNS analysis returned no PTR hostnames or forward resolutions. No TLS certificates, email authentication (SPF/DMARC), or web services were identified. The address is not classified as Tor exit node, proxy, CDN, hosting, mobile, or residential infrastructure.
Threat Indicators
- Abuse Confidence Score: Not calculated
- Blacklist Count: 0
- Threat Feeds: No active threat feed matches
- Known Campaigns: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Neighborhood Analysis
The /24 subnet (108.62.56.0/24) shows elevated abuse activity:
- Abuse Density: 0.7461 (High)
- Total Siblings: 256
- Active Siblings: 132
- Threat Siblings: 191
- Inherited Risk Score: 29
- Neighbor Risk Distribution: 4 high-risk, 93 medium-risk, 3 low-risk IPs
Observation History
Nineteen observations were recorded, with the most recent activity detected on 2026-06-24. Multiple signal types were observed including routing, threat, services, ownership, reputation, and geolocation data. The IP demonstrated persistent activity patterns during this observation window.
Control Plane Data
- Operator Score: 0.1304 (Minimal)
- Route Changes (30d): 0
- DNSSEC: Valid
- DNSBL Listed Count: 2 of 8 total lists
Recommended Security Actions
The following firewall rules are recommended for immediate implementation:
iptables:
```
iptables -A INPUT -s 108.62.56.167 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 108.62.56.167 drop
```
nginx:
```
deny 108.62.56.167;
```
pfSense:
```
108.62.56.167/32
```
Cloudflare WAF:
```json
{
"description": "Block 108.62.56.167 β IPDebrief risk score 50",
"action": "block",
"filter": {
"expression": "ip.src eq 108.62.56.167"
}
}
```
AWS WAF:
```json
{
"Addresses": ["108.62.56.167/32"],
"Description": "IPDebrief risk 50"
}
```
Analyst Notes
While the IP itself shows no active threat indicators, its placement within a high-abuse-density subnet warrants continued monitoring. The neighborhood analysis indicates 191 of 256 sibling IPs are associated with threats. SOC analysts should monitor for any changes in service activation or behavioral patterns from this address or adjacent IPs in the /24 block. Recommended actions should be combined with additional threat signals before enforcement.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LeaseWeb USA, Inc. Seattle |
| ASN | AS396190 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 2 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 24% | 2 | 3 |
| Overall | 18% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:52 UTC |
| Last Seen | 2026-06-26 18:11:52 UTC |
| Profile Built | 2026-06-25 00:41:10 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 20 |
Full dossier details are available via our API.