# IP INTELLIGENCE BRIEFING: 173.234.225.245
Classification: Moderate Risk / High Abuse Neighborhood
Date: 2026-06-19
Prepared For: SOC Analysts
---
## EXECUTIVE SUMMARY
IP 173.234.225.245 presents moderate risk (Score: 50) with no active threat indicators. The IP resides in a high-abuse colocation hosting environment operated by Leaseweb USA, Inc. (ASN 394380) in Dallas, TX. No open services or known malicious activity detected on the target itself.
---
## NETWORK CLASSIFICATION
- Organization: Leaseweb USA, Inc. (ASN: 394380)
- Infrastructure Type: Colocation Hosting / Game Server Provider
- Network Role: Choopa/GameServers hosting facility
- Location: Dallas, Texas, United States (2500km accuracy radius)
- Routing Status: Route unstable (isRouteStable: false)
- DNSSEC: Valid
- Services: None detected (firewalled/no services)
---
## THREAT INDICATORS
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- DNSBL Listed: 2 of 8 lists
- Threat Feeds: None correlated
- Campaign Matches: None
---
## NEIGHBORHOOD ANALYSIS (173.234.225.0/24)
- Abuse Density: 0.8477 (High Abuse Classification)
- Threat Siblings: 217 of 256 IPs
- Active Siblings: 184
- Risk Distribution: 100 medium, 0 high, 0 low
- Inherited Risk Score: 33
Assessment: The /24 subnet exhibits elevated abuse density typical of shared hosting environments. The target IP itself shows no direct malicious indicators despite neighborhood risk.
---
## OBSERVATION HISTORY
- Total Observations: 42 signals recorded
- Recent Classification: High Abuse (abuse_density: 0.89)
- Operator Score: 0.1304 (Minimal)
- Threat Persistence: Not persistent (persistence_days: 0)
- Ownership Changes: 0
The IP demonstrates stability with no significant behavioral shifts over the observation period.
---
## RELATIONSHIP GRAPH
- Total Relationships: 115
- Primary Links: Same Network (LU-79 networks)
- Associated Entities: Multiple network-level relationships indicating infrastructure sharing
---
## SECURITY RECOMMENDATIONS
Firewall Actions:
```bash
# iptables
iptables -A INPUT -s 173.234.225.245 -j DROP
# nftables
nft add rule inet filter input ip saddr 173.234.225.245 drop
```
WAF/Cloud Security:
- Cloudflare WAF: Block IP (risk score 50)
- AWS WAF: Add 173.234.225.245/32 to block list
Decision Context:
- Risk score of 50 indicates moderate concern
- No active threat indicators on target IP
- Neighborhood context suggests elevated baseline risk
- Recommend monitoring rather than immediate blocking
- Combine with additional signals before enforcement
---
## ANALYST NOTES
This IP represents a hosting infrastructure asset within a high-density abuse neighborhood. The absence of open services and threat indicators suggests legitimate use, though the subnet's abuse density warrants continued monitoring. No immediate blocking recommended without corroborating threat signals.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 17% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 26% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:02 UTC |
| Last Seen | 2026-06-27 10:31:05 UTC |
| Profile Built | 2026-06-28 04:37:46 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 44 |
Full dossier details are available via our API.