Intelligence Briefing: IP Address 108.62.56.92/32
Summary:
The IP address 108.62.56.92/32 was observed in various network activities over the monitored period. Based on gathered data, the address has been associated with both legitimate and potentially malicious activities. The intelligence gathered from available tools provides insights into the nature of its engagements, relationships, and neighborhood characteristics.
Observation History:
- The IP address was frequently involved in web traffic to multiple domains, some of which are known for hosting a variety of content, including media and forums.
- There were several instances of outgoing connections to IP ranges commonly associated with content delivery networks (CDNs). This suggests legitimate use for accessing media and web resources.
- The address was also observed initiating connections to IP addresses linked to known threat actors, raising potential security concerns.
Relationships:
- The IP address has connections to both reputable service providers and entities flagged in threat intelligence databases for hosting suspicious activities.
- There were repeated connections to IP addresses associated with known malware distribution networks, indicating possible exploitation or compromise.
Neighborhood Data:
- The IP address is part of a subnet with a mixed reputation. The surrounding IP range includes both benign and suspicious IPs, suggesting a shared hosting environment.
- Traffic analysis indicates the presence of other IPs within the same subnet exhibiting similar patterns of connections to both legitimate and questionable destinations.
Threat Intelligence Narrative:
The IP address 108.62.56.92/32 has been observed engaging in dual-use activities, participating in both legitimate content delivery and potentially malicious connections. The association with known threat actors and malware distribution networks warrants caution. The mixed nature of its neighborhood and frequent interactions with both reputable and flagged IPs suggest the potential for exploitation or compromise. Network defenders should monitor traffic to and from this IP for unusual patterns or connections to known malicious entities and consider implementing additional security controls to mitigate potential risks.
Recommendations:
- Continuous monitoring of traffic related to this IP address is advised.
- Implement network segmentation and access controls to limit potential exposure.
- Conduct regular threat intelligence updates to maintain awareness of any changes in the behavior associated with this IP address.
This intelligence briefing is intended to assist SOC teams in understanding the risk profile associated with IP 108.62.56.92/32 and to guide defensive measures accordingly.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LeaseWeb USA, Inc. Seattle |
| ASN | AS396190 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:52 UTC |
| Last Seen | 2026-06-26 18:11:51 UTC |
| Profile Built | 2026-06-24 19:33:25 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.