## IP INTELLIGENCE BRIEFING: 173.234.226.48/32
Executive Summary
The target IP 173.234.226.48 was analyzed and classified as a Moderate Risk (50/100) hosting infrastructure asset located in Dallas, TX, United States. The IP is associated with Leaseweb USA, Inc. (ASN 394380) operating under Choopa/GameServers provider designation. The IP presents elevated neighborhood-level risk with an abuse density of 0.8672 within its /24 subnet.
Infrastructure Profile
Ownership: Leaseweb USA, Inc. (ASN 394380, ARI)
Geolocation: Dallas, Texas, United States (US)
Network Classification: Colocation Hosting / Firewalled Infrastructure
Service Status: No open ports or services detected; network role classified as "Firewalled / No Services"
Threat Assessment
Risk Score: 50 (Moderate Risk)
Threat Indicators:
- DNSBL listings: 2 of 8 total lists
- Known attacker: No
- Spam source: No
- Tor exit node: No
- Blacklist count: 0
Abuse Confidence: Not explicitly scored, but subnet-level abuse density of 0.8672 indicates high-abuse classification.
Neighborhood Analysis
Subnet: 173.234.226.0/24
Subnet Statistics:
- Total siblings: 256
- Active siblings: 226
- Threat siblings: 222
- Inherited risk: 34
Neighbor Risk Distribution (sampled 100 neighbors):
- High risk: 0
- Medium risk: 100
- Low risk: 0
The /24 subnet demonstrates consistent medium-risk classification across sampled neighbor IPs, with all neighbors returning a risk score of 50 and authority score of 50.
Historical Observation Trends
Total Observations: 44 signals tracked
Key Historical Findings:
- Recent subnet abuse density fluctuations observed between 0.7148 and 0.8672
- Operator score maintained at "Minimal" (0.2174) across multiple observation periods
- No persistent malicious activity detected
- Single threat observation recorded in observation history
- Ownership stability: No changes observed
Relationship Graph
Total Relationships: 233 identified
Primary Relationship Type: Same Network (LU-79) - 228+ entries of network-level relationships identified
Recommended Security Actions
Primary Recommendation: No specific recommendations generated; however, the following blocking rules are available for implementation:
Firewall Rules:
- iptables: `iptables -A INPUT -s 173.234.226.48 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 173.234.226.48 drop`
- nginx: `deny 173.234.226.48;`
- pfSense: `173.234.226.48/32`
- Cloudflare WAF: Block rule with expression `ip.src eq 173.234.226.48`
- AWS WAF: Address set `173.234.226.48/32`
SOC Analyst Guidance
The IP 173.234.226.48 resides within a high-abuse density hosting environment (Choopa/GameServers). While the IP itself shows no active malicious indicators or open services, the subnet-level context (0.8672 abuse density, 222 threat siblings) warrants defensive posture consideration. The IP is classified as firewalled hosting infrastructure with no current services exposed.
Actionable Recommendations:
1. Block inbound traffic at perimeter firewall using provided rules
2. Monitor for outbound connections from internal hosts to this IP
3. Consider subnet-level blocking (173.234.226.0/24) if threat correlation exists
4. Validate against internal threat intelligence for any associated malicious activity
Risk Level: Moderate - Block recommended based on neighborhood context despite lack of direct threat indicators on the target IP.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 4 |
| routing | 22% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:03 UTC |
| Last Seen | 2026-06-27 10:40:58 UTC |
| Profile Built | 2026-06-28 04:45:44 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 49 |
Full dossier details are available via our API.