# IP Intelligence Briefing: 173.234.226.13/32
Classification: Moderate Risk | Date: June 19, 2026
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP 173.234.226.13 operates from Dallas, Texas (US) within a colocation hosting environment under Leaseweb USA, Inc. (ASN 394380). The IP exhibits a moderate risk score of 50 and is deployed in a high-abuse subnet (173.234.226.0/24) with 86.72% abuse density. No active threat indicators were detected, though the subnet classification warrants defensive consideration.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 50 (Moderate) |
| **Organization** | Leaseweb USA, Inc. |
| **ASN** | 394380 |
| **Location** | Dallas, TX, US |
| **Infrastructure Type** | Colocation Hosting |
| **Network Role** | Choopa/GameServers Provider |
| **Service Purpose** | Firewalled / No Services |
---
## Threat Assessment
Current Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Listed: 2 lists (out of 8 total)
- Known Campaigns: None
Behavioral Analysis
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None (firewalled)
- Service Banner: None
- Email Reputation: Not assessed (no hosted domains)
---
## Neighborhood Analysis
Subnet: 173.234.226.0/24
- Abuse Density: 86.72% (HIGH ABUSE)
- Total Siblings: 256
- Active Siblings: 226
- Threat Siblings: 222
- Inherited Risk Score: 34
Risk Distribution (Sampled): 100 medium-risk neighbors observed; all sampled IPs returned risk score of 50.
---
## Historical Observations
Observation Count: 40 signals recorded
- Observation Period: June 18-19, 2026
- Operator Score: 0.1304 (Minimal) - consistent across all observations
- Route Stability: False
- DNSSEC Valid: True
- Route Changes (30d): 0
Recent signals indicate persistent minimal operator risk, though subnet-level abuse remains elevated.
---
## Network Relationships
- Total Relationships: 148
- Primary Association: Network LU-79 (Same Network)
- Correlated Entities: Multiple network-level relationships detected
---
## Recommended Actions
Based on the IP's risk profile and high-abuse subnet classification:
Firewall Rules
```bash
# iptables
iptables -A INPUT -s 173.234.226.13 -j DROP
# nftables
nft add rule inet filter input ip saddr 173.234.226.13 drop
# nginx
deny 173.234.226.13;
# pfSense
173.234.226.13/32
```
Cloud Platform Recommendations
- Cloudflare WAF: Block IP β Risk score 50
- AWS WAF: Block address 173.234.226.13/32
---
## Intelligence Narrative
The target IP (173.234.226.13) is a firewalled colocation hosting address with no active services or open ports. While no direct threat indicators were observed, the IP resides within a subnet exhibiting 86.72% abuse density with 222 of 256 sibling IPs classified as threats. The consistent operator score of 0.1304 across 40 observations suggests stable but elevated contextual risk. The IP's association with Choopa/GameServers infrastructure and Leaseweb USA indicates a shared hosting environment commonly exploited for compromised or misconfigured systems.
Assessment: The subnet-level abuse density presents elevated contextual risk. While this specific IP shows no active malicious behavior, defensive blocking is recommended due to the high-abuse environment classification.
---
Product: IPDebrief | Copyright © 2026 Jason Alberino
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 4 |
| routing | 51% | 1 | 10 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 28% | 10 | 25 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:02 UTC |
| Last Seen | 2026-06-27 10:35:06 UTC |
| Profile Built | 2026-06-28 04:42:16 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 53 |
Full dossier details are available via our API.