# Intelligence Briefing: IP 108.62.56.59/32
## Executive Summary
IP address 108.62.56.59 is classified as Moderate Risk with a risk score of 40. The endpoint is hosted by LeaseWeb USA, Inc. Seattle (ASN: 396190) and operates in a high-abuse density subnet (108.62.56.0/24). While no direct threat indicators are present on this specific IP, the neighborhood exhibits elevated abuse activity requiring monitoring.
## Ownership and Geolocation
- Organization: LeaseWeb USA, Inc. Seattle
- ASN: 396190
- Geolocation: United States, Washington, Seattle
- CIDR Block: 108.62.56.0/24
- Geographic Consensus: Valid (geoPlausible: true)
## Threat Profile
- Risk Score: 40/100 (Moderate)
- Blacklist Status: Currently unlisted (0 direct blacklists)
- DNSBL Presence: Listed on 1 of 8 total DNSBL feeds
- Operator Classification: Minimal (0.2174)
- Route Stability: Unstable (isRouteStable: false)
- DNSSEC: Valid
- Network State: Firewalled/No Services (no open ports detected)
## Historical Analysis
Analysis of 24 signal observations reveals temporal threat evolution:
- June 2026 Activity: Multiple observations recorded with varying confidence levels
- DNSBL Listings: One observation flagged DNSBL listings with high severity on 2026-06-17
- Threat Persistence: No persistent malicious behavior detected
- Campaign Correlation: No known campaign matches or correlated IPs identified
## Network Neighborhood Assessment
Subnet analysis for 108.62.56.0/24 indicates:
- Abuse Density: 0.7305 (High Abuse Classification)
- Active Siblings: 118 of 256 total IPs
- Threat Siblings: 187 threat-identified IPs in neighborhood
- Risk Distribution: High: 4, Medium: 96, Low: 0
The subnet exhibits elevated abuse activity, though the target IP itself shows minimal direct threat indicators.
## Recommended Security Actions
Based on risk assessment, the following defensive measures are recommended:
| System | Recommended Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 108.62.56.59 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 108.62.56.59 drop` |
| **nginx** | `deny 108.62.56.59;` |
| **pfSense** | Block 108.62.56.59/32 |
| **Cloudflare WAF** | Block with expression: `ip.src eq 108.62.56.59` |
| **AWS WAF** | Add 108.62.56.59/32 to block list |
## Intelligence Narrative
IP 108.62.56.59 presents a moderate risk profile typical of cloud infrastructure hosted by LeaseWeb. The endpoint shows no direct malicious indicators but operates within a subnet exhibiting high abuse density (0.7305), with 187 of 256 sibling IPs flagged as threats. Historical observations indicate intermittent DNSBL listings, suggesting potential abuse history despite current clean status.
The IP's firewalled state with no detected services suggests either a dormant endpoint or active mitigation. Route instability flags warrant monitoring for potential infrastructure changes. Given the neighborhood's elevated abuse profile, recommend implementing the suggested firewall rules and monitoring for any behavioral changes, particularly DNSBL listings or service enumeration activity.
## Key Indicators
- IP: 108.62.56.59
- Organization: LeaseWeb USA, Inc. Seattle
- ASN: 396190
- Risk Score: 40
- Threat Classification: Moderate Risk
- Action Required: Implement firewall rules; monitor neighborhood activity
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LeaseWeb USA, Inc. Seattle |
| ASN | AS396190 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 26% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:52 UTC |
| Last Seen | 2026-06-26 18:11:51 UTC |
| Profile Built | 2026-06-24 19:39:13 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.