Threat Intelligence Briefing for IP: 173.234.226.175/32
Summary:
The IP address 173.234.226.175/32 was observed in connection with a range of activities indicative of both legitimate and potentially malicious behavior. The analysis included data from multiple sources, focusing on network activities, reputation assessments, and neighborhood associations.
Observation History:
1. Network Traffic:
- The IP was identified as a source of outbound traffic to various domains, some of which are associated with known ad networks and content delivery networks (CDNs). This suggests potential involvement in legitimate content distribution or advertising activities.
2. Reputation:
- Threat intelligence databases flagged this IP with a moderate risk rating. Past incidents include associations with command-and-control (C2) traffic related to botnet activities, suggesting potential misuse by threat actors.
3. Service and Host Analysis:
- The IP was linked to services that periodically scan for vulnerabilities, indicating potential reconnaissance activities. Such behavior is commonly seen in both penetration testing and malicious scanning.
Relationships and Associations:
1. Known Threats:
- The IP has been reported in past security bulletins as part of a larger cluster suspected of distributing malware. The specific nature of malware involved was not definitively identified but included characteristics typical of ransomware and information-stealing malware.
2. Traffic Patterns:
- Analysis of traffic patterns revealed intermittent bursts of activity to known malicious domains, suggesting possible exfiltration attempts or data harvesting operations.
Neighborhood Data:
1. Subnet Analysis:
- The IP belongs to a subnet with a mixed reputation, hosting both legitimate enterprises and entities flagged for malicious activities. This mixed environment underscores the need for careful traffic monitoring to differentiate between benign and malicious traffic.
2. Geographic Location:
- The IP is geolocated to a region known for hosting a variety of internet services. This geographic context aligns with the presence of both legitimate and questionable activities.
Actionable Recommendations:
- Monitoring and Logging:
- Implement enhanced logging and monitoring for traffic originating from or directed to this IP. Pay particular attention to any unusual patterns that may indicate malicious activity.
- Blocking and Filtering:
- Consider implementing network rules to block or filter traffic to and from this IP, especially during periods of unusual activity or when connected to known malicious domains.
- Threat Intelligence Updates:
- Regularly update threat intelligence feeds to capture any new associations or activities related to this IP, ensuring timely responses to emerging threats.
- Incident Response Preparation:
- Prepare incident response protocols in case of detection of malicious activity linked to this IP, including potential malware infections or data breaches.
This intelligence briefing provides a comprehensive overview of the activities and associations of IP 173.234.226.175/32, enabling SOC analysts to make informed decisions regarding network security and threat mitigation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 4 |
| routing | 43% | 1 | 7 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 26% | 10 | 22 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:03 UTC |
| Last Seen | 2026-06-27 11:02:15 UTC |
| Profile Built | 2026-06-28 05:08:20 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 52 |
Full dossier details are available via our API.