## IP Intelligence Briefing: 173.234.225.205/32
Executive Summary
The IP address 173.234.225.205 belongs to Leaseweb USA, Inc. (ASN 394380) and is registered to Choopa/GameServers infrastructure in Dallas, TX. The IP maintains a moderate risk score of 50 and operates within a colocation hosting environment.
Ownership and Network Classification
The IP is owned by Leaseweb USA, Inc. under ASN 394380 and is classified as Choopa/GameServers infrastructure. The network operates as colocation hosting with no cloud, CDN, VPN, or proxy characteristics. The BGP prefix 173.234.224.0/22 routes through this ASN with stable routing.
Geographic Location
Geolocation data identifies the IP in Dallas, TX, US with 2,500 km accuracy radius. Geolocation consensus is confirmed across multiple sources, and the IP is not a bogon address.
Threat Indicators and Reputation
Current threat indicators show no known attacker status, no Tor exit node status, and no spam source designation. The IP is not listed on any known threat feeds. DNSBL enumeration reveals 2 listings out of 8 total lists, indicating minimal operator-level reputation concerns. The operator score registers at 0.1304 (Minimal).
Network Neighborhood Analysis
The /24 subnet (173.234.225.0/24) exhibits high abuse classification with an abuse density of 0.8477. Of 256 total siblings in the subnet, 217 were identified as threat siblings, with 184 active siblings observed. All 100 neighboring IPs returned a uniform risk score of 50 with medium risk classification. The IP inherited a risk score of 33 from subnet characteristics.
Service and Port Analysis
The IP shows no open ports and is classified as "Firewalled / No Services." No TLS certificates, HTTP banners, or reverse DNS entries were detected. The IP has no associated hosted domains or email authentication records (no SPF, DMARC, or TXT records).
Historical Observations
Thirty-seven signal observations were recorded. Recent observations (June 18-19) confirm consistent ASN 394380 association with the 173.234.225.0/24 prefix. Operator scoring consistently returned "Minimal" classification across multiple timestamps. The IP is not persistently malicious based on temporal analysis.
Network Relationships
The IP maintains 113 relationships with related entities, primarily same-network connections to LU-79 network segments, indicating infrastructure relationships within the provider's broader network architecture.
Recommended Security Actions
Based on the risk profile of 50, blocking rules were generated for multiple platforms:
- iptables: `iptables -A INPUT -s 173.234.225.205 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 173.234.225.205 drop`
- nginx: `deny 173.234.225.205;`
- pfSense: `173.234.225.205/32`
- Cloudflare WAF: Block IP 173.234.225.205 with expression `ip.src eq 173.234.225.205`
- AWS WAF: Add 173.234.225.205/32 to rule set with description "IPDebrief risk 50"
Intelligence Assessment
This IP represents Choopa/GameServers infrastructure within Leaseweb's colocation hosting environment. The moderate risk score correlates with the high-abuse subnet characteristics. No active malicious indicators were observed, but the neighborhood abuse density warrants consideration when evaluating traffic from this IP. The IP should be evaluated in context with observed network behavior and additional correlation data before enforcement actions.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 36% | 1 | 4 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 26% | 9 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:02 UTC |
| Last Seen | 2026-06-27 10:24:19 UTC |
| Profile Built | 2026-06-28 04:29:25 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 47 |
Full dossier details are available via our API.