IP Intelligence Briefing: 173.234.226.77
Date: 2026-06-14
---
**1. Core Profile**
- Risk Score: 50 (Moderate Risk)
- Ownership: Leaseweb USA, Inc. (ASN 394380)
- Geolocation: Dallas, TX, US (Data Center)
- Network Role: Colocation Hosting (Provider: Choopa/GameServers)
- Threat Indicators: No active malicious signals, no known abuse or spam sources.
---
**2. Network Context**
- Subnet: 173.234.226.0/24
- Abuse Density: 71.88% (High Abuse)
- Neighbor Risk: 28 inherited risk score; 184 of 207 active IPs in subnet show threat activity.
- Subnet Classification: "high_abuse" with elevated risk.
---
**3. Historical Observations**
- Observation Count: 42 entries (last 30 days)
- Trend: Minimal risk scores consistently; no significant spikes in threat activity.
- Validation: ICMP blocked, preventing full geolocation verification.
---
**4. Relationships**
- Linked Networks: Multiple connections to network "LU-79" (likely a subnet or organizational identifier).
- Services: No open ports, no TLS/HTTP services detected.
- DNS: No PTR records, no email authentication (SPF/DKIM) configured.
---
**5. Actionable Insights**
- SOC Recommendation:
- Monitor traffic from this subnet due to high abuse density.
- Investigate potential correlation with neighboring IPs showing threat activity.
- Verify provider compliance, as the hosting provider (Choopa/GameServers) may host compromised assets.
- Firewall Rules: Consider blocking or rate-limiting traffic from this subnet if it aligns with known malicious patterns.
---
Conclusion:
The IP is part of a high-risk subnet associated with a hosting provider. While the IP itself shows no direct malicious activity, the surrounding network's abuse density warrants further scrutiny. SOC teams should prioritize monitoring this subnet for lateral movement or command-and-control activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 43% | 2 | 5 |
| routing | 22% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 27% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:03 UTC |
| Last Seen | 2026-06-27 10:45:49 UTC |
| Profile Built | 2026-06-28 04:52:28 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 46 |
Full dossier details are available via our API.