# IP Intelligence Briefing: 173.234.225.192/32
Classification: Moderate Risk | Priority: Medium | Date: Current
---
## Executive Summary
IP 173.234.225.192 is a colocation hosting address operated by Leaseweb USA, Inc. (ASN 394380) in Dallas, TX. While the IP itself shows no direct threat indicators, the subnet exhibits elevated abuse density (83.59%), suggesting the infrastructure is frequently utilized for malicious activity. No open ports or active services were detected on the target IP.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 173.234.225.192/32 |
| **Risk Score** | 50/100 (Moderate) |
| **Provider** | Choopa/GameServers (Leaseweb USA, Inc.) |
| **ASN** | 394380 |
| **Location** | Dallas, TX, US |
| **Infrastructure Type** | Colocation Hosting |
| **Network Role** | Hosting Provider |
| **DNSBL Listed** | 2 of 8 total lists |
| **Open Ports** | None detected |
| **Known Tor Exit/Attacker** | No |
---
## Risk Indicators
Direct Threat Signals: None. The IP is not flagged as a known attacker, spam source, or Tor exit node.
Contextual Risk Factors:
- Abuse Density: The /24 subnet (173.234.225.0/24) shows 83.59% abuse density with 214 of 256 sibling IPs classified as threats
- Inherited Risk Score: 33/100 from neighborhood context
- DNSBL Presence: Listed on 2 of 8 threat feeds, indicating prior abuse history
---
## Temporal Analysis
Observation history contains 41 signal observations. Recent assessments (June 2026) consistently report minimal operator scores (0.1739). No persistent malicious behavior detected; the IP is not classified as persistently malicious.
---
## Related Entities
113 relationships identified, primarily network-level associations (LU-79). No organizational, certificate, or hostname relationships linked to this specific address.
---
## Recommended Actions
Based on the moderate risk profile and neighborhood context, consider the following:
Blocking Recommendations:
```bash
# iptables
iptables -A INPUT -s 173.234.225.192 -j DROP
# nftables
nft add rule inet filter input ip saddr 173.234.225.192 drop
# Cloudflare WAF
action: block
expression: ip.src eq 173.234.225.192
# AWS WAF
Addresses: 173.234.225.192/32
```
Additional Considerations:
- Monitor for emergence of open ports or service banners
- Evaluate blocking adjacent high-risk siblings within the /24 subnet if traffic patterns justify it
- Review connection logs for any abuse originating from this subnet prefix (173.234.225.0/24)
---
Intelligence Source: IPDebrief | Status: Current | Action Required: Review firewall rules and monitoring thresholds
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 43% | 1 | 8 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 27% | 10 | 23 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:02 UTC |
| Last Seen | 2026-06-27 10:22:09 UTC |
| Profile Built | 2026-06-28 04:27:09 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 54 |
Full dossier details are available via our API.