# IP Intelligence Briefing: 173.234.225.219/32
## Executive Summary
IP address 173.234.225.219 is a colocation hosting resource operated by Leaseweb USA, Inc. (AS394380) in Dallas, Texas. The IP carries a Moderate Risk score of 50 with evidence of DNSBL listing (2 of 8 lists) and is situated in a high-abuse density subnet (173.234.225.0/24) where 84.77% of active IPs show abuse indicators. The infrastructure is firewalled with no publicly accessible services.
## Ownership and Geolocation
- Organization: Leaseweb USA, Inc.
- ASN: 394380 (Choopa/GameServers)
- Network Role: Colocation Hosting / Game Server Provider
- Location: Dallas, Texas, US
- Infrastructure Classification: Colocation Hosting (not CDN, cloud, or proxy)
## Threat Indicators
- DNSBL Status: Listed on 2 of 8 DNSBL feeds
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Correlation: None detected
- Threat Persistence: 0 days observed
## Network Behavior Analysis
- Service Status: No open ports detected; infrastructure is firewalled
- DNS Resolution: No forward resolution confirmed; no PTR records
- Email Reputation: No SPF or DMARC records configured
- Route Stability: BGP prefix shows 0 route changes in last 30 days but marked as not stable
## Subnet Neighborhood Assessment (173.234.225.0/24)
- Abuse Density: 0.8477 (high_abuse classification)
- Active Siblings: 184 of 256 total IPs
- Threat Siblings: 217 IPs flagged as threats
- Risk Distribution: 100 medium-risk IPs, 0 high-risk, 0 low-risk
- Inherited Risk Score: 33 (from subnet context)
## Historical Observations
47 total observations recorded with recent activity on June 18-19, 2026. DNS operator score consistently rated at 0.2174 (Minimal). Multiple blacklist listings detected with high-severity categorizations.
## Relationship Graph
169 relationships identified, all categorized as "Same Network" relationships (LU-79), indicating strong correlation with other IPs within the same /24 subnet.
## Recommended Actions
Firewall Rules:
- iptables: `iptables -A INPUT -s 173.234.225.219 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 173.234.225.219 drop`
- nginx: `deny 173.234.225.219;`
- pfsense: Block 173.234.225.219/32
- Cloudflare WAF: Block expression `ip.src eq 173.234.225.219`
- AWS WAF: Add address `173.234.225.219/32`
## Analyst Notes
This IP resides in a high-abuse density subnet where 217 of 256 total IPs show threat indicators. While the individual IP shows no open services and is firewalled, its location within a heavily abused /24 network suggests potential for abuse-related activity. The moderate risk score reflects DNSBL listings rather than active attack signatures. Consider blocking at the network edge due to neighborhood risk context, but monitor for actual malicious activity rather than relying solely on IP reputation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 45% | 1 | 7 |
| services | 17% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 27% | 10 | 23 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:02 UTC |
| Last Seen | 2026-06-27 10:26:43 UTC |
| Profile Built | 2026-06-28 04:31:49 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 54 |
Full dossier details are available via our API.