# IP Intelligence Briefing: 108.62.63.124/32
Classification: Moderate Risk / Infrastructure IP
Report Date: June 2026
Analyst: IPDebrief Intelligence Team
## Executive Summary
Analyst assessed IP address 108.62.63.124 as a Moderate Risk (score: 50/100) infrastructure endpoint operated by LeaseWeb USA, Inc. Seattle (ASN: 396190). The address currently exhibits no active threat indicators, maintains no open services, and shows no evidence of malicious activity. However, the IP resides within a high-abuse density subnet (108.62.63.0/24), which contextualizes its risk posture.
## Ownership and Geolocation
The IP belongs to LeaseWeb USA, Inc. Seattle, registered under AS396190 in the ARIN RIR. Geolocation data places the address in Seattle, Washington (US), with coordinates validated as plausible. The control plane indicates route instability (isRouteStable: false), suggesting the BGP prefix 108.62.56.0/21 experienced changes within the observation window.
## Network State and Services
Network scanning revealed no open ports; the system shows as "Firewalled / No Services." DNS analysis returned no PTR hostnames and no forward resolution records. No TLS certificates or HTTP responses were observed. The address does not appear in any known Tor exit node databases, VPN, proxy, or CDN configurations.
## Threat Indicators
Threat intelligence feeds reported no indicators of compromise. The IP is not flagged as a known attacker, spam source, or Tor exit node. Blacklist analysis returned zero entries. No email authentication records (SPF, DMARC) were detected for associated domains. The IP was listed on 2 out of 8 DNSBLs checked, indicating historical reputation concerns but no current active listing.
## Neighborhood Analysis
The /24 subnet (108.62.63.0/24) classified as "high_abuse" with an abuse density of 0.6641. Among 256 total sibling addresses, 176 were active and 170 were flagged as threats. This neighborhood-level context suggests the IP may share infrastructure with compromised hosts, though the target IP itself shows no malicious behavior.
## Historical Observations
The system recorded 29 signal observations over the monitoring period. Recent observations (June 18β23, 2026) consistently showed "Minimal" risk with an operator score of 0.2174. The address demonstrated threat persistence of zero days and is not classified as persistently malicious.
## Relationships
The IP maintains 140 relationship links, primarily to the same network prefix 108-62-56-0/21. No certificate matches or correlated campaign indicators were detected.
## Recommended Actions
Based on the moderate risk score and neighborhood abuse context, the following firewall rules are recommended for defensive hardening:
- iptables: `iptables -A INPUT -s 108.62.63.124 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 108.62.63.124 drop`
- nginx: `deny 108.62.63.124;`
- Cloudflare WAF: Block with expression `ip.src eq 108.62.63.124`
- AWS WAF: Add 108.62.63.124/32 to blocked addresses list
## Intelligence Assessment
This IP represents a low-priority defensive target. While the address itself shows no active malicious behavior, the high-abuse neighborhood warrants continued monitoring. The absence of open services and threat indicators suggests legitimate hosting infrastructure. Analysts should monitor for changes in the subnet's abuse profile and consider blocking if the IP begins exhibiting suspicious patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LeaseWeb USA, Inc. Seattle |
| ASN | AS396190 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 28% | 2 | 3 |
| Overall | 22% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:01 UTC |
| Last Seen | 2026-06-26 18:11:59 UTC |
| Profile Built | 2026-06-26 22:34:10 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.