# IP Intelligence Briefing: 173.234.225.138/32
## Executive Summary
IP 173.234.225.138 operates as a moderate-risk address (risk score 50) within the 173.234.225.0/24 subnet under Leaseweb USA, Inc. (ASN 394380). The IP is classified as colocation hosting infrastructure with no active services. Despite showing no direct threat indicators, the subnet exhibits high abuse density (0.8789), and the IP is recommended for blocking due to its association with a high-abuse neighborhood.
## Infrastructure Profile
- ASN: 394380 (Leaseweb USA, Inc.)
- Organization: Choopa/GameServers
- Location: Dallas, TX, US
- Infrastructure Type: Colocation Hosting
- Network Role: Firewalled/No Services
- BGP Prefix: 173.234.225.0/24
- Route Stability: Stable (delegation age: 3,947 days)
## Threat Assessment
- Risk Score: 50 (Moderate Risk)
- Abuse Confidence: Not elevated
- Known Threats: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- DNSBL Status: Listed on 2 of 8 total lists
- Campaign Association: None
## Network Neighborhood Analysis
The 173.234.225.0/24 subnet demonstrates elevated abuse characteristics:
- Abuse Density: 0.8789 (high)
- Classification: high_abuse
- Total Subnet Siblings: 256
- Active Siblings: 184
- Threat Siblings: 225
- Neighbor Risk Distribution: 100 medium-risk (score 50), 0 high-risk, 0 low-risk
This subnet-wide context indicates the IP operates within a hosting environment with significant abuse activity, warranting defensive consideration despite the individual IP's lack of direct threat signals.
## Service & DNS Observations
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- DNS PTR Records: None
- Forward Resolution: Not confirmed
- Hosted Domains: 0
## Temporal Analysis
Forty-six signal observations tracked over the observation period. Recent signals (June 23-24, 2026) show minimal threat levels with operator scores ranging 0.2174-0.25. No significant threat escalation detected in the historical record.
## Recommended Security Actions
Based on risk profile, the following blocking measures are recommended:
| Platform | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 173.234.225.138 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 173.234.225.138 drop` |
| **nginx** | `deny 173.234.225.138;` |
| **pfSense** | `173.234.225.138/32` |
| **Cloudflare WAF** | Block with filter expression: `ip.src eq 173.234.225.138` |
| **AWS WAF** | Add address: `173.234.225.138/32` |
## Intelligence Notes
- The IP's high neighborhood abuse density (0.8789) and classification as "high_abuse" suggest elevated risk from lateral threat activity within the /24 subnet.
- While the IP itself shows no direct threat indicators, the subnet's abuse characteristics warrant continued monitoring.
- Relationship graph indicates 134 connections, primarily to same-network entities (LU-79), consistent with colocation hosting infrastructure.
- No evidence of persistent malicious activity or campaign correlation.
---
*Report generated: 2026-06-24*
*Data source: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | 173.234.225.0/24 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 33% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 35% | 3 | 6 |
| reputation | 28% | 1 | 3 |
| geolocation | 26% | 2 | 3 |
| Overall | 27% | 12 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:02 UTC |
| Last Seen | 2026-06-27 10:13:00 UTC |
| Profile Built | 2026-06-28 04:19:06 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 52 |
Full dossier details are available via our API.