# IP Intelligence Briefing: 108.62.56.21/32
## Executive Summary
IP 108.62.56.21 presents as a high-risk address (score 80/100) with elevated threat indicators and subnet abuse density. The IP belongs to LeaseWeb USA, Inc. Seattle (ASN 396190) and is located in Washington state. The address was firewalled with no active services detected, yet maintained persistent blacklist presence.
## Risk Profile
The IP achieved a risk score of 80, classified as High Risk. Control plane analysis showed the BGP prefix 108.62.56.0/21 with unstable routing. The address was listed on three DNSBLs out of eight total checks. Operator score remained minimal at 0.2174, indicating limited authoritative infrastructure characteristics. Ownership assignment to LeaseWeb USA, Inc. Seattle occurred with no provider or authority score elevation.
## Threat Indicators
Threat analysis revealed no open ports or active services. DNS resolution showed no PTR hostnames and forward resolution remained unconfirmed. The IP did not exhibit Tor exit node, cloud provider, CDN, VPN, or hosting characteristics. Behavioral analysis showed zero honeypot hits, zero enumeration strikes, and no WAF violations. However, the IP accumulated 23 signal observations over the monitoring period, including multiple blacklist listings with high severity ratings observed as recently as June 2024.
## Geographic and Network Context
Geolocation data placed the IP in Seattle, Washington, United States, with a 2500 km accuracy radius and geo-plausibility confirmed. The parent subnet 108.62.56.0/24 exhibited high abuse density (0.7305) with 187 threat siblings out of 256 total addresses. Risk distribution across the subnet showed 3 high-risk addresses, 97 medium-risk, and 0 low-risk addresses, with most neighboring IPs maintaining a risk score of 50.
## Relationship Analysis
The IP maintained 53 recorded relationships, primarily consisting of network-level associations to 108.62.56.0/24. No hostname, organization, or certificate relationships were identified in the relationship graph. The subnet classification indicated high abuse activity, with 118 active siblings and 187 threat-sibling addresses within the /24 block.
## Historical Trends
Observation history showed 23 signal events over the monitoring period. Multiple blacklist listings appeared with high severity ratings, including entries from June 2024. Geolocation signals consistently identified the United States. Operator scores remained at minimal classification levels throughout the observation window. No persistent malicious behavior was detected over the threat persistence duration.
## Recommended Actions
SOC analysts should implement the following defensive measures:
Immediate Actions:
- Increase logging verbosity and review recent activity from this IP address
- Consider implementing blocking rules pending correlation with internal threat data
Firewall Recommendations:
- iptables: `iptables -A INPUT -s 108.62.56.21 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 108.62.56.21 drop`
- nginx: `deny 108.62.56.21;`
- pfSense: Add 108.62.56.21/32 to block list
- Cloudflare WAF: Block IP with expression `ip.src eq 108.62.56.21`
- AWS WAF: Add 108.62.56.21/32 to IP set
## Intelligence Assessment
The IP represents a high-risk address associated with a hosting provider infrastructure in Seattle. While no active services were detected, the persistent blacklist presence and high-risk neighbor profile indicate potential for abuse. Monitoring and logging are recommended before implementing blocking actions, correlating with internal threat intelligence before enforcement.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LeaseWeb USA, Inc. Seattle |
| ASN | AS396190 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:51 UTC |
| Last Seen | 2026-06-26 18:11:51 UTC |
| Profile Built | 2026-06-24 19:40:23 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.