# IP Intelligence Briefing: 173.234.226.1
## Executive Summary
IP address 173.234.226.1 is a colocation hosting endpoint located in Dallas, Texas, operated by Leaseweb USA, Inc. (ASN 394380). The IP carries a moderate risk score of 50 and resides within a /24 subnet exhibiting high abuse density (0.8672), with 222 of 256 sibling IPs flagged as threat sources. No open services or active threat indicators were observed on this specific endpoint.
## Infrastructure Profile
- Organization: Leaseweb USA, Inc.
- ASN: 394380
- Location: Dallas, TX, US (Geo consensus verified)
- Infrastructure Type: Colocation Hosting
- Network Role: Choopa/GameServers provider
- CIDR Block: 173.234.226.0/24
## Network Classification
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- TLS/SSL Certificates: None
- Hosted Domains: None
- Email Auth: No SPF/DMARC records configured
## Threat Indicators
- Abuse Confidence Score: Not available
- Blacklist Status: Listed on 2 of 8 DNSBL feeds
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
## Neighborhood Analysis
The /24 subnet (173.234.226.0/24) demonstrates significant abuse concentration:
- Abuse Density: 0.8672 (classified as high_abuse)
- Total Siblings: 256
- Active Siblings: 226
- Threat Siblings: 222
- Risk Distribution: 100% medium risk (riskScore 50) across sampled neighbors
## Control Plane Observations
- Route Stability: Unstable (isRouteStable: false)
- Route Changes (30d): 0
- RPKI State: Not validated
- Operator Score: 0.1304 (Minimal)
- DNSSEC: Valid
- MoAS: No
## Temporal Analysis
- Observation Count: 39 historical observations
- Threat Persistence Days: 0
- Is Persistently Malicious: No
- Ownership Changes: 0
- Recent Trend: Consistent operator score of 0.1304 across multiple observations (June 18-19, 2026)
## Geolocation Validation
- Validation Status: ICMP blocked - unable to validate
- Distance: 7997.4 km
- Minimum Possible RTT: 160ms
## Recommended Actions
Based on the moderate risk profile and high-abuse subnet context:
1. Monitor: Implement passive monitoring for any new service openings or port activity
2. Blocklists: Review and maintain entries on 2 active DNSBL feeds
3. Network Context: Exercise caution due to high-abuse /24 neighborhood; correlate with adjacent IPs before allowing inbound traffic
4. No Immediate Mitigation: No specific firewall rules required at this time; endpoint shows no active exploitation indicators
## Intelligence Assessment
This IP represents a passive hosting endpoint within a high-abuse colocation infrastructure. While the specific address shows no active malicious behavior, the subnet's abuse density warrants defensive vigilance. The absence of open services reduces immediate risk, but the neighborhood context suggests the infrastructure may be exploited by third parties. Continuous monitoring is recommended, with particular attention to any service enumeration or port activity that emerges.
---
*Report generated based on IPDebrief intelligence data. Classification: Defensive Security Analysis.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 4 |
| routing | 22% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:02 UTC |
| Last Seen | 2026-06-27 10:33:05 UTC |
| Profile Built | 2026-06-28 04:40:01 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 43 |
Full dossier details are available via our API.