# IP Intelligence Briefing: 173.234.226.109
Date: 2026-06-19
Classification: Moderate Risk
Intel Source: IPDebrief
---
## Executive Summary
IP address 173.234.226.109 presents a moderate-risk profile with a risk score of 50. The IP is hosted on Leaseweb USA, Inc. infrastructure (ASN: 394380) in Dallas, TX, and operates within a high-abuse density subnet (173.234.226.0/24). While no active threat indicators were observed, the surrounding network environment shows elevated abuse characteristics.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 173.234.226.109/32 |
| **Organization** | Leaseweb USA, Inc. |
| **ASN** | 394380 |
| **Location** | Dallas, TX, United States |
| **Network Role** | Colocation Hosting (Choopa/GameServers) |
| **Infrastructure Type** | Hosting Provider |
| **Risk Score** | 50 (Moderate) |
Service Enumeration
- Open Ports: None detected
- DNS Resolution: No forward resolution
- PTR Records: None
- Service Status: Firewalled / No Services
- TLS/Certificates: None observed
---
## Threat Assessment
Current Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0 (direct)
- DNSBL Listings: 2 of 8 total lists
- Known Campaigns: None identified
Risk Breakdown
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Operator Score: 0.1304 (Minimal)
---
## Network Environment Analysis
Subnet Profile (173.234.226.0/24)
- Abuse Density: 0.7188 (High)
- Classification: high_abuse
- Total Siblings: 256
- Active Siblings: 236
- Threat Siblings: 184
- Inherited Risk: 28
The /24 subnet exhibits elevated abuse density with 184 of 256 sibling IPs flagged as threats. This indicates the hosting provider's infrastructure is frequently leveraged for malicious activities, though the specific IP under analysis shows no direct threat indicators.
---
## Historical Observations
Signal History (41 Observations)
- Recent Pattern: Consistent monitoring with stable characteristics
- Operator Score Trend: Maintained at 0.1304 across multiple observations
- Abuse Density: Sustained at 0.7188 in recent observations
- Persistence: No persistent malicious behavior detected
- Campaign Correlation: Zero correlated IPs or certificate matches
---
## Relationship Mapping
Network Relationships
- 150 relationships identified
- Primary Association: LU-79 network (Leaseweb infrastructure)
- Network Stability: Multiple same-network references indicating established infrastructure
---
## Recommended Actions
Based on the risk profile and neighborhood context, the following defensive measures are recommended:
Firewall Rules
- iptables: `iptables -A INPUT -s 173.234.226.109 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 173.234.226.109 drop`
- nginx: `deny 173.234.226.109;`
- pfSense: `173.234.226.109/32`
WAF/Cloud Rules
- Cloudflare WAF: Block IP 173.234.226.109 (risk score 50)
- AWS WAF: Add 173.234.226.109/32 to block list
SOC Analyst Guidance
- No direct threat indicators require immediate investigation
- Monitor for any service changes or new port openings
- Consider blocking at perimeter if policy permits due to high-abuse subnet context
- Validate any traffic from this IP against baseline behavior
---
## Conclusion
IP 173.234.226.109 is a hosting infrastructure address with moderate risk characteristics. While it lacks direct threat indicators, the high-abuse density of its subnet warrants defensive posture. No immediate threat action is required, but traffic filtering is recommended as a precautionary measure.
Status: Monitor
Priority: Medium
Action Required: Optional blocking
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 5 |
| routing | 45% | 1 | 9 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 29% | 10 | 25 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:03 UTC |
| Last Seen | 2026-06-27 10:51:11 UTC |
| Profile Built | 2026-06-28 04:55:52 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 56 |
Full dossier details are available via our API.