Threat Intelligence Briefing: IP Address 173.234.225.115/32
Summary:
The IP address 173.234.225.115 was observed engaging in network activity that may be of interest to SOC teams. The following details encapsulate the comprehensive analysis derived from multiple data sources.
Observation History:
- Activity Patterns: The IP address exhibited consistent network traffic during regular business hours, suggesting a potential link to legitimate operations. However, sporadic increases in activity during off-hours were detected, indicating potential for malicious usage.
- Geolocation: The IP address is geolocated in the United States, specifically within the region of Virginia. This aligns with known hosting services and data centers in the area.
Relationships:
- Associated Domains: The IP address is linked to several domains, some of which are associated with web hosting services. Notably, a few domains have been flagged for hosting suspicious content, including phishing attempts and malware distribution.
- Known Hosts: The IP address has been identified as part of a larger infrastructure used by a service provider. Some of the associated entities have a history of hosting malicious sites, although this is not conclusive for all linked domains.
Neighborhood Data:
- Subnet Analysis: The subnet of the IP address includes several other IPs with a history of benign activity. However, a subset of addresses within the same subnet have been involved in command and control (C2) communications for known malware families.
- Traffic Analysis: Network traffic patterns from this IP show both inbound and outbound connections to multiple international IPs. Some of these connections have been traced to known malicious actors and botnets.
Actionable Intelligence:
- Monitoring Recommendations: Given the mixed activity patterns and associations with potentially malicious domains, it is recommended to monitor traffic from and to this IP for unusual activity, particularly during off-hours.
- Threat Indicators: SOC analysts should consider adding the IP address to watchlists for anomaly detection systems, focusing on traffic spikes and connections to known malicious IPs.
- Domain Scrutiny: Domains associated with this IP should be subject to further analysis to identify any phishing or malware-hosting activities. Implementing DNS filtering for these domains is advisable.
Conclusion:
While the IP address 173.234.225.115/32 has legitimate connections, its associations with suspicious domains and irregular traffic patterns necessitate vigilant monitoring. By integrating this intelligence into defensive strategies, SOC teams can better protect against potential threats originating from this IP.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | 173.234.225.0/24 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 33% | 2 | 4 |
| services | 20% | 2 | 3 |
| ownership | 32% | 3 | 5 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 29% | 12 | 22 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:02 UTC |
| Last Seen | 2026-06-27 10:09:08 UTC |
| Profile Built | 2026-06-28 04:15:40 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 52 |
Full dossier details are available via our API.