# IP Intelligence Briefing: 108.62.63.215/32
Date: June 2024
Classification: Moderate Risk Infrastructure IP
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP 108.62.63.215 is a moderate-risk (50/100) infrastructure address belonging to LeaseWeb USA, Inc. Seattle (ASN: 396190). The IP shows no active malicious indicators but resides within a high-abuse density subnet (108.62.63.0/24) where 66% of addresses exhibit abuse characteristics. The IP is currently firewalled with no open services, DNS, or active threat signals.
---
## Risk Assessment
| Metric | Value |
|---|---|
| **Risk Score** | 50 (Moderate) |
| **Abuse Confidence** | Not scored |
| **Blacklist Count** | 0 |
| **DNSBL Listed** | 2 of 8 lists |
| **Threat Persistence** | None |
Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit: No
- Campaign Likelihood: None
---
## Ownership & Geolocation
- Organization: LeaseWeb USA, Inc. Seattle
- ASN: 396190
- Location: Seattle, WA, US
- BGP Prefix: 108.62.56.0/21
- Network Role: Provider Infrastructure (Firewalled/No Services)
---
## Neighborhood Analysis (108.62.63.0/24)
| Metric | Value |
|---|---|
| **Subnet Size** | 256 IPs |
| **Active IPs** | 176 |
| **Threat Siblings** | 170 |
| **Abuse Density** | 0.6641 (High) |
| **Inherited Risk** | 26 |
Risk Distribution in /24:
- High Risk: 0 IPs
- Medium Risk: 100 IPs
- Low Risk: 0 IPs
The subnet exhibits elevated abuse density, though the specific IP (108.62.63.215) shows no active malicious behavior.
---
## Historical Observations
35 total observations recorded. Recent observations consistently show "Minimal" threat levels with 0/8 signals detected across multiple time windows (June 23-24, 2024). No persistent malicious activity detected.
---
## Network Behavior
- Open Ports: None
- DNS Resolution: Forward confirmation not confirmed
- Hosted Domains: 0
- Email Authentication: SPF/DMARC not configured
- TLS/HTTP Services: Not detected
- Traceroute: 12 hops via Comcast, Lumen
- Geo Validation: ICMP blocked (unable to validate)
---
## Recommended Security Actions
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 108.62.63.215 -j DROP
# nftables
nft add rule inet filter input ip saddr 108.62.63.215 drop
```
WAF Recommendations:
- Cloudflare: Block IP with filter expression `ip.src eq 108.62.63.215`
- AWS WAF: Add `108.62.63.215/32` to blocked addresses
Note: Actions are probabilistic and should be validated against other threat signals before deployment.
---
## Threat Intelligence Narrative
IP 108.62.63.215 presents a moderate-risk profile with no active malicious indicators. However, the subnet-level context warrants attention: 108.62.63.0/24 demonstrates significant abuse density (66.41%) with 170 threat siblings among 176 active IPs. While this specific address shows no services, open ports, or blacklist associations, the neighborhood context suggests it may be part of compromised or misconfigured infrastructure.
SOC Analyst Recommendations:
1. Monitor inbound traffic from this IP for anomalies
2. Consider subnet-level blocking if false positives are not a concern
3. Verify legitimacy of LeaseWeb infrastructure allocation
4. Implement rate limiting if traffic is observed
The IP is currently classified as provider infrastructure with no services. Blocking is recommended based on subnet abuse patterns, but operational context should guide final decision.
---
Report Generated: June 2024
Data Sources: IPDebrief Intelligence Platform
Confidence Level: Medium
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LeaseWeb USA, Inc. Seattle |
| ASN | AS396190 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 28% | 2 | 3 |
| reputation | 33% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:01 UTC |
| Last Seen | 2026-06-26 18:12:00 UTC |
| Profile Built | 2026-06-26 22:15:47 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 35 |
Full dossier details are available via our API.