# IP Intelligence Briefing: 173.234.225.46/32
Classification: Moderate Risk (Score: 50)
Date: 2026-06-24
Analyst: IPDebrief Intelligence Platform
---
## Executive Summary
IP address 173.234.225.46 is a moderate-risk infrastructure address operated by Leaseweb USA, Inc. (ASN 394380) in Dallas, Texas. The IP is hosted on Choopa/GameServers infrastructure within a colocation environment. The address exhibits characteristics typical of hosting services with no active web services detected. Neighborhood analysis indicates elevated abuse density within the /24 subnet.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 50/100 (Moderate Risk) |
| **Organization** | Leaseweb USA, Inc. |
| **ASN** | 394380 |
| **Geolocation** | Dallas, TX, US |
| **Infrastructure** | Colocation Hosting (Choopa/GameServers) |
| **Network Role** | Hosting Provider |
| **DNSBL Listings** | 2 of 8 lists |
---
## Threat Indicators
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
- Blacklist Count: 0
- Active Threat Indicators: None detected
- Campaign Correlations: 0
---
## Neighborhood Analysis
The IP resides within subnet 173.234.225.0/24, which shows:
- Abuse Density: 0.8477 (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 184
- Threat Siblings: 217
- Inherited Risk Score: 33
Sample neighbor risk distribution across 100 sampled IPs: 100 medium-risk (score 50), 0 high-risk, 0 low-risk. This pattern indicates systematic hosting infrastructure rather than concentrated malicious activity.
---
## Historical Observations
35 observations recorded since earliest detection. Recent signals (June 23-24, 2026) show:
- Consistent ASN 394380 (Leaseweb USA) attribution
- Operator score: Minimal (0/8)
- No escalation in risk profile over observation period
- Routing signals stable across 30-day window
---
## Network Relationships
145 relationships identified, predominantly same-network associations with LU-79 network. Strong correlation with Leaseweb infrastructure network indicates legitimate hosting environment with shared address space.
---
## Recommended Security Actions
Based on risk profile, the following firewall rules are recommended:
iptables:
```
iptables -A INPUT -s 173.234.225.46 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 173.234.225.46 drop
```
nginx:
```
deny 173.234.225.46;
```
Cloudflare WAF:
```
{"description":"Block 173.234.225.46 β IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 173.234.225.46"}}
```
AWS WAF:
```
{"Addresses":["173.234.225.46/32"],"Description":"IPDebrief risk 50"}
```
---
## Assessment Notes
The IP address operates within a shared colocation hosting environment typical of game servers and web hosting services. No active malicious services were detected on the address. The neighborhood's elevated abuse density reflects the nature of shared hosting infrastructure rather than specific malicious activity from this IP.
Recommendation: Monitor traffic patterns; consider blocking if this IP is observed initiating connections to internal systems or exhibiting anomalous behavior.
---
*Generated by IPDebrief Intelligence Platform β Defensive Security Analysis*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 43% | 1 | 6 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 27% | 9 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:01 UTC |
| Last Seen | 2026-06-27 09:57:35 UTC |
| Profile Built | 2026-06-28 04:02:54 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 45 |
Full dossier details are available via our API.