# IP Intelligence Briefing: 173.234.225.48/32
Classification: Moderate Risk | Date: 2026-06-19
## Executive Summary
IP 173.234.225.48 is a hosting/colocation address operated by Leaseweb USA, Inc. (ASN 394380) from Dallas, TX. The IP presents moderate risk (score: 50) with minimal operator scores and is classified under Choopa/GameServers network role. The address shows no open services (firewalled) and is listed on 2 of 8 DNSBLs.
## Network Profile
- Owner: Leaseweb USA, Inc. (ASN 394380)
- Geolocation: Dallas, TX, US (radius: 2500km)
- Network Block: 173.234.225.0/24
- BGP Prefix: 173.234.225.0/24 (origin ASN 394380)
- Route Stability: Not stable (route changes observed in 30d)
- RPKI/Irr: Inconsistent routing state
## Threat Indicators
- Risk Score: 50/100 (Moderate)
- DNSBL Status: Listed on 2 of 8 blacklists
- Threat Indicators: None currently active
- Campaign Association: No known campaign matches
- Campaign Likelihood: Not applicable
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
## Neighborhood Analysis (173.234.225.0/24)
- Total Subnet Siblings: 256
- Active Siblings: 184
- Threat Siblings: 216
- Abuse Density: High (0.8438)
- Neighborhood Risk: Inherited risk score of 33 from subnet
- Classification: High abuse zone
## Relationship Graph
- Total Relationships: 122
- Primary Connections: Same network (LU-79) relationships
- Associated Entities: Multiple network-level connections to LU-79 subnet
## Signal History
- Total Observations: 37
- Recent Operator Score: 0.1304 (Minimal)
- Threat Persistence: 0 days
- Ownership Changes: 0
- Recent Activity: Multiple signals observed June 18-19, 2026 with consistent minimal operator scores
## Recommended Actions
The following rules are recommended for defensive security controls:
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 173.234.225.48 -j DROP
# nftables
nft add rule inet filter input ip saddr 173.234.225.48 drop
# nginx
deny 173.234.225.48;
# pfSense
pass inet proto tcp from any to any port 80,443 src 173.234.225.48/32
```
Cloud Security:
- Cloudflare WAF: Block rule with expression `ip.src eq 173.234.225.48`
- AWS WAF: Add address 173.234.225.48/32 to rule set
## Intelligence Assessment
This IP belongs to a high-abuse-density subnet (173.234.225.0/24) with 216 threat siblings out of 256 total. Despite the IP's moderate individual risk score, the neighborhood context suggests elevated threat activity. The hosting environment (Choopa/GameServers) is commonly associated with compromised infrastructure. DNSBL listing on 2 of 8 lists corroborates potential malicious activity.
Recommendation: Apply blocking rules with consideration of legitimate use cases. Monitor for false positives given the subnet's high abuse density.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 45% | 1 | 7 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 28% | 9 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:01 UTC |
| Last Seen | 2026-06-27 09:57:55 UTC |
| Profile Built | 2026-06-28 04:02:54 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 46 |
Full dossier details are available via our API.