IPDebrief

173.234.225.87

IP Intelligence Dossier
Your IP: 216.73.217.135
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## IP Intelligence Briefing: 173.234.225.87/32

Classification: Moderate Risk (Score: 50/100)

Date: Current Analysis

Source: IPDebrief Intelligence Platform

---

Executive Summary

IP 173.234.225.87 is a hosting infrastructure address owned by Leaseweb USA, Inc. (ASN 394380), located in Dallas, TX. The IP is classified as Choopa/GameServers colocation hosting with no active services. While the individual IP shows moderate risk, the /24 subnet exhibits high abuse density (0.8359) with 214 of 256 sibling IPs flagged as threats. No current active threat indicators detected.

---

Network Profile

AttributeValue
**IP Address**173.234.225.87/32
**Risk Score**50 (Moderate)
**Organization**Leaseweb USA, Inc.
**ASN**394380
**Location**Dallas, TX, US
**Infrastructure Type**Colocation Hosting
**Provider**Choopa/GameServers
**Network Role**Hosting Provider

---

Technical Observations

---

Threat Intelligence

---

Neighborhood Analysis (173.234.225.0/24)

MetricValue
**Total Subnet IPs**256
**Active Siblings**179
**Threat Siblings**214
**Abuse Density**0.8359 (High)
**Inherited Risk**33/100
**Risk Distribution**100 Medium, 0 High, 0 Low

The subnet exhibits elevated abuse activity consistent with shared hosting infrastructure. Neighbor IPs show uniform risk scoring (50/100), indicating systematic risk characteristics across the /24 block.

---

Historical Trends

39 total observations recorded. Recent signal history (June 2026) shows consistent "Minimal" operator score (0.1304) across multiple measurements. No significant risk escalation detected over the observation period.

---

Relationship Graph

142 relationships identified, primarily "Same Network" associations (LU-79 network references). Strong network-level clustering observed within the hosting infrastructure.

---

Recommended Security Actions

Assessment: Block recommended based on moderate risk score and high-abuse subnet classification.

Firewall Rules:

Note: Recommendations are probabilistic. Combine with additional threat signals before implementation.

---

Analyst Notes: This IP represents shared hosting infrastructure within a high-abuse-density subnet. While individual IP risk is moderate, the neighborhood context suggests potential for abuse. Monitor for any service activation or behavioral changes that would warrant escalated response.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionTX
CityDallas
Timezoneβ€”
Latitude32.78
Longitude-96.80

🏒 Ownership & Registration

OrganizationLeaseweb USA, Inc.
ASNAS394380
Network Nameβ€”
CIDR Block173.234.225.0/24
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
Hosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
23%
24
routing
27%
23
services
12%
22
ownership
35%
35
reputation
27%
13
geolocation
32%
23
Overall26%1220
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:05:02 UTC
Last Seen2026-06-27 10:04:26 UTC
Profile Built2026-06-28 10:10:28 UTC
Data FreshnessLive
Signal Types22
Total Observations48
πŸ” 22 signal types Β· 48 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.