IPDebrief

173.234.226.48

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## IP INTELLIGENCE BRIEFING: 173.234.226.48/32

Executive Summary

The target IP 173.234.226.48 was analyzed and classified as a Moderate Risk (50/100) hosting infrastructure asset located in Dallas, TX, United States. The IP is associated with Leaseweb USA, Inc. (ASN 394380) operating under Choopa/GameServers provider designation. The IP presents elevated neighborhood-level risk with an abuse density of 0.8672 within its /24 subnet.

Infrastructure Profile

Ownership: Leaseweb USA, Inc. (ASN 394380, ARI)

Geolocation: Dallas, Texas, United States (US)

Network Classification: Colocation Hosting / Firewalled Infrastructure

Service Status: No open ports or services detected; network role classified as "Firewalled / No Services"

Threat Assessment

Risk Score: 50 (Moderate Risk)

Threat Indicators:

Abuse Confidence: Not explicitly scored, but subnet-level abuse density of 0.8672 indicates high-abuse classification.

Neighborhood Analysis

Subnet: 173.234.226.0/24

Subnet Statistics:

Neighbor Risk Distribution (sampled 100 neighbors):

The /24 subnet demonstrates consistent medium-risk classification across sampled neighbor IPs, with all neighbors returning a risk score of 50 and authority score of 50.

Historical Observation Trends

Total Observations: 44 signals tracked

Key Historical Findings:

Relationship Graph

Total Relationships: 233 identified

Primary Relationship Type: Same Network (LU-79) - 228+ entries of network-level relationships identified

Recommended Security Actions

Primary Recommendation: No specific recommendations generated; however, the following blocking rules are available for implementation:

Firewall Rules:

SOC Analyst Guidance

The IP 173.234.226.48 resides within a high-abuse density hosting environment (Choopa/GameServers). While the IP itself shows no active malicious indicators or open services, the subnet-level context (0.8672 abuse density, 222 threat siblings) warrants defensive posture consideration. The IP is classified as firewalled hosting infrastructure with no current services exposed.

Actionable Recommendations:

1. Block inbound traffic at perimeter firewall using provided rules

2. Monitor for outbound connections from internal hosts to this IP

3. Consider subnet-level blocking (173.234.226.0/24) if threat correlation exists

4. Validate against internal threat intelligence for any associated malicious activity

Risk Level: Moderate - Block recommended based on neighborhood context despite lack of direct threat indicators on the target IP.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionTX
CityDallas
Timezoneβ€”
Latitude32.78
Longitude-96.80

🏒 Ownership & Registration

OrganizationLeaseweb USA, Inc.
ASNAS394380
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
Hosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
24%
24
routing
22%
11
services
17%
23
ownership
17%
23
reputation
28%
13
geolocation
32%
23
Overall23%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:05:03 UTC
Last Seen2026-06-27 10:40:58 UTC
Profile Built2026-06-28 04:45:44 UTC
Data FreshnessLive
Signal Types22
Total Observations49
πŸ” 22 signal types Β· 49 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.