IPDebrief

173.234.225.216

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP INTELLIGENCE BRIEFING: 173.234.225.216/32

Classification: Moderate Risk | Risk Score: 40 | Status: Active Threat Indicator

1. OWNERSHIP & INFRASTRUCTURE

The IP address 173.234.225.216 is registered to ASN 394380, operated by Leaseweb USA, Inc. (Choopa/GameServers). The network is located in Dallas, Texas, United States, within the Dallas metro area. The infrastructure type is classified as colocation hosting. The IP has no open ports or active services detected during scanning.

2. THREAT ASSESSMENT

The IP address carries a risk score of 40, designated as Moderate Risk. Threat indicators show the IP is not identified as a known attacker, Tor exit node, proxy, or VPN service. No spam source indicators or known campaign associations were detected. The IP appears on one DNS blacklist (of 8 total lists checked), though the primary blacklist count shows zero.

3. NETWORK CONTEXT & NEIGHBORHOOD ANALYSIS

The IP resides in the 173.234.225.0/24 subnet, classified as high_abuse with an abuse density score of 0.8945. Of the 256 total sibling addresses in the subnet, 188 were active during assessment, with 229 flagged as threats. The inherited risk from the subnet is 35. All 100 sampled neighbors in the immediate neighborhood showed medium-level risk (risk score 50), indicating systemic risk within the /24 block.

4. OBSERVATION HISTORY

Forty-seven observations were recorded for this IP. The most recent signals (2026-06-24) confirm the provider classification as Choopa/GameServers with colocation hosting infrastructure. Geolocation confidence was low (0.35), though consistent with US deployment. The IP was detected on eight blacklist sources, with the maximum severity listed as high.

5. RELATIONSHIP ANALYSIS

The relationship graph contains 163 entries, all of the "Same Network" type (LU-79), indicating extensive network-level associations within the same routing prefix. No hostname, organization, or certificate relationships were identified beyond the network scope.

6. CONTROL PLANE DATA

BGP prefix 173.234.225.0/24 originates from ASN 394380. Route stability is marked as false with zero route changes in the past 30 days. DNSSEC validation is active, and CAA records are present. Operator score is 0.2174, labeled as Minimal.

7. RECOMMENDED ACTIONS

Firewall and WAF rules were generated for the following platforms:

8. INTELLIGENCE SUMMARY

IP 173.234.225.216 is a Choopa/GameServers hosting infrastructure address with moderate risk rating. The IP is part of a high-abuse-density subnet (0.8945) where 89% of addresses show threat indicators. While the IP itself shows no active service exposure, the neighborhood context suggests systemic abuse patterns. The single DNSBL listing with high severity provides actionable intelligence for blocking. Recommended defensive posture: implement firewall rules to block the IP address at perimeter and WAF layers.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionTX
CityDallas
Timezoneβ€”
Latitude32.78
Longitude-96.80

🏒 Ownership & Registration

OrganizationLeaseweb USA, Inc.
ASNAS394380
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
Hosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
40%
25
routing
22%
11
services
20%
23
ownership
17%
23
reputation
28%
13
geolocation
30%
23
Overall26%1018
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:05:02 UTC
Last Seen2026-06-27 10:26:12 UTC
Profile Built2026-06-28 04:31:49 UTC
Data FreshnessLive
Signal Types22
Total Observations48
πŸ” 22 signal types Β· 48 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.