IPDebrief

173.234.225.125

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: 173.234.225.125

Classification: Moderate Risk / High-Abuse Neighborhood

Date: 2026-06-19

---

## EXECUTIVE SUMMARY

IP address 173.234.225.125 is hosted within Leaseweb USA, Inc. (ASN 394380) infrastructure in Dallas, TX. The IP carries a risk score of 50 (Moderate Risk) and is classified within a high-abuse density subnet (173.234.225.0/24) with an abuse density rating of 0.8672. While no direct threat indicators or active services were detected, the surrounding neighborhood exhibits significant malicious activity, warranting defensive monitoring.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
**Organization**Leaseweb USA, Inc.
**ASN**394380
**RIR**ARIN
**Geolocation**Dallas, TX, US
**Network Role**Colocation Hosting / Choopa/GameServers
**Infrastructure Type**Hosting
**CIDR Block**173.234.225.0/24

No open ports or active services were detected on the IP address. The infrastructure is classified as firewalled with no exposed services.

---

## THREAT ASSESSMENT

Direct Threat Indicators

Control Plane Indicators

---

## NEIGHBORHOOD ANALYSIS (173.234.225.0/24)

The /24 subnet demonstrates elevated abuse characteristics:

MetricValue
**Abuse Density**0.8672 (HIGH)
**Subnet Classification**high_abuse
**Total Siblings**256
**Active Siblings**184
**Threat Siblings**222
**Inherited Risk**34

All sampled neighbors within the subnet exhibit a uniform risk score of 50, indicating systemic abuse patterns across this hosting block. The 222 threat siblings represent approximately 87% of the total subnet, confirming this is a high-risk hosting environment.

---

## OBSERVATION HISTORY

Total Observations: 44

Recent signal observations indicate consistent abuse density metrics (0.8672) and sustained high_abuse classification. Operator score remains stable at 0.2174 (Minimal). DNSSEC validation has been maintained throughout the observation period. No ownership changes detected.

---

## RELATIONSHIP ANALYSIS

Total Relationships: 150

Multiple same-network relationships (LU-79) identified, indicating the IP shares network infrastructure with numerous associated entities.

---

## RECOMMENDED ACTIONS

Based on the risk profile and neighborhood context, the following defensive measures are recommended:

Firewall Rules

```bash

# iptables

iptables -A INPUT -s 173.234.225.125 -j DROP

# nftables

nft add rule inet filter input ip saddr 173.234.225.125 drop

```

Application-Level Blocking

```nginx

# nginx

deny 173.234.225.125;

# Cloudflare WAF

Expression: ip.src eq 173.234.225.125

Action: Block

# AWS WAF

Addresses: 173.234.225.125/32

Description: IPDebrief risk 50

```

Operational Recommendation

Consider implementing subnet-wide blocking for 173.234.225.0/24 given the 0.8672 abuse density and 87% threat sibling ratio. Monitor for lateral movement attempts from neighboring IPs.

---

## ASSESSMENT

This IP presents moderate risk primarily due to its placement within a high-abuse density hosting subnet. While no active threats or services were detected on the IP itself, the neighborhood context warrants defensive blocking and ongoing monitoring. The infrastructure is typical of game server/co-location hosting environments commonly associated with abuse activities.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionTX
CityDallas
Timezoneβ€”
Latitude32.78
Longitude-96.80

🏒 Ownership & Registration

OrganizationLeaseweb USA, Inc.
ASNAS394380
Network Nameβ€”
CIDR Block173.234.225.0/24
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
Hosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
26%
24
routing
36%
24
services
17%
23
ownership
32%
35
reputation
28%
13
geolocation
30%
23
Overall28%1222
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:05:02 UTC
Last Seen2026-06-27 10:10:48 UTC
Profile Built2026-06-28 04:17:57 UTC
Data FreshnessLive
Signal Types25
Total Observations53
πŸ” 25 signal types Β· 53 observations collected
This report is generated from 25+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.