# IP Intelligence Briefing: 173.234.225.73/32
## Executive Summary
IP 173.234.225.73 is a moderate-risk hosting infrastructure address assigned to Leaseweb USA, Inc. (ASN 394380). While the IP itself maintains a risk score of 50/100, the associated /24 subnet (173.234.225.0/24) exhibits high abuse density, with 84% of active sibling IPs classified as threats. The IP is classified as Choopa/GameServers colocation hosting with firewalling enabled but shows DNSBL listings on 2 of 8 reputation feeds.
## Technical Profile
- Risk Score: 50 (Moderate Risk)
- Organization: Leaseweb USA, Inc.
- ASN: 394380
- Location: Dallas, Texas, US
- Infrastructure Type: Colocation Hosting (Choopa/GameServers)
- Network Role: Hosting with "Firewalled / No Services" status
- DNSBL Status: Listed on 2 of 8 total blacklist feeds
- Operator Score: 0.1304 (Minimal)
- Route Stability: False (control plane data indicates instability)
## Threat Context
The IP resides in a high-abuse density subnet (173.234.225.0/24) where:
- 214 out of 256 total sibling IPs are classified as threats
- 179 sibling IPs are currently active
- Abuse density score: 0.8359
- Risk distribution: 100 medium-risk neighbors, 0 high-risk, 0 low-risk
This contextual environment suggests the IP shares infrastructure characteristics common to abused hosting environments, despite the IP itself showing limited direct threat indicators.
## Historical Observations
Analysis of 38 signal observations reveals consistent, low-variability behavior:
- Operator scores remained stable at 0.1304 across all recent observations
- No evidence of escalating threat activity or persistent malicious behavior
- Last observation recorded: June 19, 2026
- No correlation to known threat campaigns or malware infrastructure
## Relationship Analysis
The IP maintains 138 documented relationships, primarily within the same network (LU-79). Limited relationship diversity suggests the IP operates as isolated infrastructure rather than as part of a coordinated threat actor network. No certificate associations or cross-organization links were identified.
## Recommended Security Actions
Based on the risk profile, the following defensive measures are recommended:
Firewall Recommendations:
- iptables: `iptables -A INPUT -s 173.234.225.73 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 173.234.225.73 drop`
Application-Level Controls:
- nginx: `deny 173.234.225.73;`
- pfSense: `173.234.225.73/32`
Cloud/WAF Controls:
- Cloudflare WAF: Block with expression `ip.src eq 173.234.225.73`
- AWS WAF: Add rule for `173.234.225.73/32`
## Intelligence Assessment
The IP presents moderate risk primarily due to its hosting environment context rather than direct malicious activity. The high abuse density of the parent subnet suggests elevated probability of compromise or abuse by neighboring IPs. The IP itself shows no current threat indicators, but the infrastructure classification (Choopa/GameServers hosting) is commonly associated with compromised servers.
Recommendation: Implement blocking at the perimeter firewall and WAF layers. Monitor for lateral movement attempts from this IP to internal resources, particularly given the neighborhood context. Consider blocking the entire /24 subnet if operational requirements permit, given the 84% threat concentration.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | 173.234.225.0/24 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 45% | 2 | 6 |
| services | 12% | 2 | 2 |
| ownership | 35% | 3 | 5 |
| reputation | 28% | 1 | 3 |
| geolocation | 26% | 2 | 3 |
| Overall | 29% | 12 | 23 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:01 UTC |
| Last Seen | 2026-06-27 10:02:06 UTC |
| Profile Built | 2026-06-28 04:07:31 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 49 |
Full dossier details are available via our API.