## IP Intelligence Briefing: 173.234.225.89/32
Classification: Moderate Risk β Colocation Hosting Infrastructure
Date Generated: 2026-06-24
---
Executive Summary
IP 173.234.225.89 is a colocation hosting address assigned to Leaseweb USA, Inc. (ASN 394380) in Dallas, TX. The address demonstrates moderate risk characteristics consistent with shared hosting infrastructure. No active malicious services were observed, but the subnet exhibits high abuse density (0.8672), indicating elevated risk from neighboring addresses.
---
Threat Profile
Risk Assessment:
- Overall Risk Score: 50/100 (Moderate)
- Classification: Colocation Hosting / Choopa GameServers
- Infrastructure Type: Colocation Hosting
- Service Status: Firewalled / No Services Detected
Threat Indicators:
- No active threat campaigns identified
- Not a known attacker or spam source
- Not a Tor exit node
- Listed on 2 of 8 DNSBLs (25% blacklist rate)
- No active threat feed matches
Network Classification:
- Provider: Leaseweb USA, Inc.
- Organization: Choopa/GameServers
- Geolocation: United States (Texas, Dallas) β 2500km accuracy
- BGP Prefix: 173.234.225.0/24
- Route Stability: Stable (3952 days delegation age)
- RPKI State: Validated
- DNSSEC: Valid
---
Neighborhood Analysis
Subnet Assessment (173.234.225.0/24):
- Abuse Density: 0.8672 (High)
- Total Siblings: 256
- Active Siblings: 184
- Threat Siblings: 222
- Inherited Risk: 34/100
The subnet demonstrates significant abuse activity with 86.72% abuse density and 222 threat-associated sibling IPs. This contextual factor elevates the risk profile despite the target IP's clean service status.
---
Observation History
Signal Timeline: 40 observations tracked
- Most Recent: 2026-06-24 12:03 UTC
- Observation Confidence: 0.29β0.60 (Low-Moderate)
- Route Stability: Minimal operator score (0.2174)
- Geolocation Consensus: US (confirmed via multiple sources)
The IP has demonstrated consistent geographic attribution to the United States with no significant temporal shifts in risk profile or service behavior.
---
Relationship Graph
Connected Entities: 139 relationships identified
- Primary relationship cluster: Same Network (LU-79)
- Multiple network-level associations detected
- No direct hostname or certificate relationships
---
Recommended Security Actions
Firewall Rule Recommendations:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 173.234.225.89 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 173.234.225.89 drop` |
| nginx | `deny 173.234.225.89;` |
| pfSense | `173.234.225.89/32` |
| Cloudflare WAF | Block β Risk score 50 |
| AWS WAF | `["173.234.225.89/32"]` β IPDebrief risk 50 |
Action Justification:
Despite the IP's clean service profile, the following factors warrant defensive blocking:
1. High-abuse subnet context (0.8672 abuse density)
2. Colocation hosting environment (shared infrastructure risk)
3. DNSBL listings (2/8 blacklists)
4. No observed services (potential for dormant malicious infrastructure)
---
Intelligence Conclusions
IP 173.234.225.89 represents a moderate-risk colocation hosting address within a high-abuse subnet. While the specific IP shows no active malicious services, the neighborhood context and infrastructure type warrant defensive blocking as a security best practice. No immediate threat indicators suggest active exploitation, but the IP should be monitored for service emergence or threat signal activity.
Recommendation: Implement blocking rules at perimeter defenses. Monitor for service activation or threat signal changes over the next 30 days.
---
*Generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | 173.234.225.0/24 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 49% | 2 | 5 |
| routing | 33% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 37% | 3 | 5 |
| reputation | 31% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 33% | 12 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:02 UTC |
| Last Seen | 2026-06-27 10:04:47 UTC |
| Profile Built | 2026-06-28 04:11:03 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 49 |
Full dossier details are available via our API.