# THREAT INTELLIGENCE BRIEFING: 108.62.59.29/32
## EXECUTIVE SUMMARY
IP address 108.62.59.29 is a moderate-risk infrastructure endpoint assigned to LeaseWeb USA, Inc. (Seattle) under ASN 396190. The IP resides in a high-abuse-density subnet (108.62.59.0/24) with significant malicious activity indicators. Current risk assessment score: 40/100.
## NETWORK OWNERSHIP & GEOLOCATION
- Organization: LeaseWeb USA, Inc. Seattle
- ASN: 396190
- Geolocation: Seattle, WA, US (RIR: ARIN)
- CIDR Block: 108.62.59.29/32
- Control Plane: BGP prefix 108.62.56.0/21, route stability: false
- DNSSEC: Valid
## RISK ASSESSMENT
- Overall Risk Score: 40 (Moderate Risk)
- Abuse Confidence: Not applicable
- Threat Indicators: None detected
- Blacklist Status: Listed on 1 of 8 threat feeds
- Service Purpose: Firewalled / No Services
## NEIGHBORHOOD ANALYSIS
The IP belongs to subnet 108.62.59.0/24 with the following characteristics:
- Abuse Density: 0.6836 (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 94
- Threat Siblings: 175
- Inherited Risk: 27
- Neighbor Risk Distribution: 100 medium-risk endpoints observed
## OBSERVATION HISTORY
Threat intelligence signals were observed across multiple dimensions:
- June 7, 2026: DNS blacklist listing detected (high severity)
- June 4, 2026: Subnet abuse density assessment confirmed high classification
- June 4, 2026: Geolocation validation completed (US, confidence 0.35)
- June 9, 2026: Control plane operator score recorded at 0.1304 (Minimal)
Total of 15 signal observations recorded, with 1 threat persistence observation.
## INFRASTRUCTURE ANALYSIS
- Open Ports: None detected
- TLS Certificates: None
- Hosted Domains: 0
- Email Authentication: SPF/DMARC not configured
- Network Role: Infrastructure (firewalled)
## RELATIONSHIP MAPPING
The IP has 65 documented relationships, predominantly network-level associations with CIDR block 108-62-56-0.
## RECOMMENDED SECURITY ACTIONS
Immediate Firewall Rules
- iptables: `iptables -A INPUT -s 108.62.59.29 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 108.62.59.29 drop`
- nginx: `deny 108.62.59.29;`
- pfSense: `108.62.59.29/32`
- Cloudflare WAF: Block IP with expression `ip.src eq 108.62.59.29`
- AWS WAF: Add address 108.62.59.29/32 to block list
## INTELLIGENCE JUSTIFICATION
The IP demonstrates multiple risk factors including blacklist presence, high-abuse-density subnet association, and lack of legitimate service indicators. While no active threat campaigns were identified, the neighborhood analysis shows 175 threat-sibling IPs within the same /24 subnet.
Action Priority: Monitor or block based on organizational risk tolerance. The moderate-risk score (40) combined with high-abuse neighborhood classification warrants defensive posture.
*Report generated using IPDebrief Intelligence Platform. All data sources verified at time of analysis.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LeaseWeb USA, Inc. Seattle |
| ASN | AS396190 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 22% | 9 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:55 UTC |
| Last Seen | 2026-06-26 18:11:54 UTC |
| Profile Built | 2026-06-25 02:48:38 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 20 |
Full dossier details are available via our API.