IP INTELLIGENCE BRIEFING: 173.234.225.216/32
Classification: Moderate Risk | Risk Score: 40 | Status: Active Threat Indicator
1. OWNERSHIP & INFRASTRUCTURE
The IP address 173.234.225.216 is registered to ASN 394380, operated by Leaseweb USA, Inc. (Choopa/GameServers). The network is located in Dallas, Texas, United States, within the Dallas metro area. The infrastructure type is classified as colocation hosting. The IP has no open ports or active services detected during scanning.
2. THREAT ASSESSMENT
The IP address carries a risk score of 40, designated as Moderate Risk. Threat indicators show the IP is not identified as a known attacker, Tor exit node, proxy, or VPN service. No spam source indicators or known campaign associations were detected. The IP appears on one DNS blacklist (of 8 total lists checked), though the primary blacklist count shows zero.
3. NETWORK CONTEXT & NEIGHBORHOOD ANALYSIS
The IP resides in the 173.234.225.0/24 subnet, classified as high_abuse with an abuse density score of 0.8945. Of the 256 total sibling addresses in the subnet, 188 were active during assessment, with 229 flagged as threats. The inherited risk from the subnet is 35. All 100 sampled neighbors in the immediate neighborhood showed medium-level risk (risk score 50), indicating systemic risk within the /24 block.
4. OBSERVATION HISTORY
Forty-seven observations were recorded for this IP. The most recent signals (2026-06-24) confirm the provider classification as Choopa/GameServers with colocation hosting infrastructure. Geolocation confidence was low (0.35), though consistent with US deployment. The IP was detected on eight blacklist sources, with the maximum severity listed as high.
5. RELATIONSHIP ANALYSIS
The relationship graph contains 163 entries, all of the "Same Network" type (LU-79), indicating extensive network-level associations within the same routing prefix. No hostname, organization, or certificate relationships were identified beyond the network scope.
6. CONTROL PLANE DATA
BGP prefix 173.234.225.0/24 originates from ASN 394380. Route stability is marked as false with zero route changes in the past 30 days. DNSSEC validation is active, and CAA records are present. Operator score is 0.2174, labeled as Minimal.
7. RECOMMENDED ACTIONS
Firewall and WAF rules were generated for the following platforms:
- iptables: DROP traffic from 173.234.225.216
- nftables: Drop rule for source address 173.234.225.216
- nginx: Deny rule for the IP address
- pfSense: Block 173.234.225.216/32
- Cloudflare WAF: Block action with expression filter on source IP
- AWS WAF: Add 173.234.225.216/32 to block list
8. INTELLIGENCE SUMMARY
IP 173.234.225.216 is a Choopa/GameServers hosting infrastructure address with moderate risk rating. The IP is part of a high-abuse-density subnet (0.8945) where 89% of addresses show threat indicators. While the IP itself shows no active service exposure, the neighborhood context suggests systemic abuse patterns. The single DNSBL listing with high severity provides actionable intelligence for blocking. Recommended defensive posture: implement firewall rules to block the IP address at perimeter and WAF layers.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 5 |
| routing | 22% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 26% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:02 UTC |
| Last Seen | 2026-06-27 10:26:12 UTC |
| Profile Built | 2026-06-28 04:31:49 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 48 |
Full dossier details are available via our API.