## IP INTELLIGENCE BRIEFING: 173.234.227.207/32
Classification: Hosting Infrastructure / Colocation Services
Risk Level: Moderate (Score: 50/100)
Status: Active Monitoring Required
---
EXECUTIVE SUMMARY
IP address 173.234.227.207 is a hosted infrastructure address assigned to Leaseweb USA, Inc. (ASN 394380) operating from Dallas, TX. The IP is classified as hosting infrastructure with no open services detected, indicating firewall protection. The immediate neighborhood exhibits exceptionally high abuse density (0.957), suggesting this IP resides within a compromised or heavily abused hosting environment.
---
OWNERSHIP & NETWORK ATTRIBUTES
- Organization: Leaseweb USA, Inc.
- ASN: 394380
- Geolocation: Dallas, TX, United States
- Network Classification: Colocation Hosting / Game Servers
- BGP Prefix: 173.234.227.0/24
- Route Stability: Unstable (isRouteStable: false)
- RPKI Status: Not configured
---
THREAT INDICATORS
- DNSBL Listings: 2 of 8 total blacklists
- Known Attacker: No
- Tor Exit Node: No
- Known Campaigns: None identified
- Spam Source: No
- Threat Persistence: Single observation; not persistently malicious
- Abuse Confidence: Not explicitly scored
---
NEIGHBORHOOD ANALYSIS (173.234.227.0/24)
- Total Subnet Size: 256 IPs
- Active Siblings: 207
- Threat Siblings: 245
- Abuse Density: 0.957 (Critical)
- Classification: High Abuse
- Risk Distribution: 100 medium-risk neighbors, 0 high-risk, 0 low-risk
Assessment: The /24 subnet demonstrates critical abuse density. This IP is surrounded by 245 threat-sibling IPs within the same network block, indicating compromised hosting infrastructure or abuse infrastructure sharing.
---
OBSERVATION HISTORY (48 observations)
Recent monitoring shows consistent "Minimal" operator score (0.2174) across multiple observations. No significant threat pattern escalation detected. The IP maintains stable operational characteristics with 1 threat observation recorded.
---
SERVICES & DNS
- Open Ports: None detected (firewalled)
- Hosted Domains: 0
- PTR Records: None
- Forward Resolution: Not confirmed
- TLS/Servers: No banner information available
---
RELATIONSHIP GRAPH
- Total Relationships: 143
- Primary Connection Type: Same Network (LU-79)
- Network Affiliation: Multiple network-level relationships indicate comprehensive routing infrastructure
---
RECOMMENDED ACTIONS
1. Block at Edge: Consider blocking at perimeter firewall due to high-abuse neighborhood context
2. Monitor for C2: Watch for outbound connections to known malicious IPs; this hosting infrastructure is frequently abused as a C2 platform
3. Threat Hunting: Investigate any inbound connections from this IP for potential compromise of internal systems
4. ISP Notification: If abuse observed, report to Leaseweb Abuse (contact available via RDAP)
5. WAF Rules: Add to Cloudflare/AWS WAF blocklists if available
---
BRIEFING COMPLETED: 173.234.227.207/32 - Moderate Risk Hosting Infrastructure in High-Abuse Environment
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 5 |
| routing | 22% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 27% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:05 UTC |
| Last Seen | 2026-06-27 11:50:36 UTC |
| Profile Built | 2026-06-28 05:57:13 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 50 |
Full dossier details are available via our API.