## IP Intelligence Briefing: 173.234.225.87/32
Classification: Moderate Risk (Score: 50/100)
Date: Current Analysis
Source: IPDebrief Intelligence Platform
---
Executive Summary
IP 173.234.225.87 is a hosting infrastructure address owned by Leaseweb USA, Inc. (ASN 394380), located in Dallas, TX. The IP is classified as Choopa/GameServers colocation hosting with no active services. While the individual IP shows moderate risk, the /24 subnet exhibits high abuse density (0.8359) with 214 of 256 sibling IPs flagged as threats. No current active threat indicators detected.
---
Network Profile
| Attribute | Value |
|---|---|
| **IP Address** | 173.234.225.87/32 |
| **Risk Score** | 50 (Moderate) |
| **Organization** | Leaseweb USA, Inc. |
| **ASN** | 394380 |
| **Location** | Dallas, TX, US |
| **Infrastructure Type** | Colocation Hosting |
| **Provider** | Choopa/GameServers |
| **Network Role** | Hosting Provider |
---
Technical Observations
- Services: No open ports detected; service banner indicates "Firewalled / No Services"
- DNS: No forward resolution; no PTR hostnames; zero hosted domains
- Email: No SPF/DMARC records; no email authentication configured
- TLS/HTTP: No TLS certificate; no HTTP headers detected
- DNSBL Status: Listed on 2 of 8 total DNSBL lists
- BGP Route: Origin ASN 394380; prefix 173.234.224.0/22; route stability flagged as false
- ICMP: Blocked during validation probe
---
Threat Intelligence
- Threat Indicators: None detected
- Tor/Proxy: Not identified as Tor exit node, proxy, or VPN
- Known Attacker: No matches in known attacker databases
- Spam Source: Not flagged
- Campaign Affiliation: No known campaign matches
- Persistence: Single threat observation; not persistently malicious
- Reputation Sources: None active
---
Neighborhood Analysis (173.234.225.0/24)
| Metric | Value |
|---|---|
| **Total Subnet IPs** | 256 |
| **Active Siblings** | 179 |
| **Threat Siblings** | 214 |
| **Abuse Density** | 0.8359 (High) |
| **Inherited Risk** | 33/100 |
| **Risk Distribution** | 100 Medium, 0 High, 0 Low |
The subnet exhibits elevated abuse activity consistent with shared hosting infrastructure. Neighbor IPs show uniform risk scoring (50/100), indicating systematic risk characteristics across the /24 block.
---
Historical Trends
39 total observations recorded. Recent signal history (June 2026) shows consistent "Minimal" operator score (0.1304) across multiple measurements. No significant risk escalation detected over the observation period.
---
Relationship Graph
142 relationships identified, primarily "Same Network" associations (LU-79 network references). Strong network-level clustering observed within the hosting infrastructure.
---
Recommended Security Actions
Assessment: Block recommended based on moderate risk score and high-abuse subnet classification.
Firewall Rules:
- iptables: `iptables -A INPUT -s 173.234.225.87 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 173.234.225.87 drop`
- nginx: `deny 173.234.225.87;`
- pfSense: `173.234.225.87/32`
- Cloudflare WAF: Block IP 173.234.225.87 (Risk Score: 50)
- AWS WAF: Add IPSet entry 173.234.225.87/32
Note: Recommendations are probabilistic. Combine with additional threat signals before implementation.
---
Analyst Notes: This IP represents shared hosting infrastructure within a high-abuse-density subnet. While individual IP risk is moderate, the neighborhood context suggests potential for abuse. Monitor for any service activation or behavioral changes that would warrant escalated response.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | 173.234.225.0/24 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 35% | 3 | 5 |
| reputation | 27% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 26% | 12 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:02 UTC |
| Last Seen | 2026-06-27 10:04:26 UTC |
| Profile Built | 2026-06-28 10:10:28 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 48 |
Full dossier details are available via our API.