# IP Intelligence Briefing: 173.234.227.63
## Executive Summary
IP address 173.234.227.63 presents a moderate-risk profile with significant neighborhood-level threat indicators. While the IP itself shows no direct malicious activity, its /24 subnet demonstrates an extreme abuse density of 0.9336, with 239 out of 256 sibling IPs classified as threats. The address operates within a colocation hosting environment and is listed on 2 DNSBLs.
---
## Network Ownership & Infrastructure
- Organization: Leaseweb USA, Inc. (ASN 394380)
- Infrastructure Type: Colocation Hosting / GameServers
- Location: Dallas, TX, US
- BGP Prefix: 173.234.224.0/22
- Network Classification: Provider (Choopa/GameServers)
---
## Risk Assessment
| Metric | Value | Assessment |
|---|---|---|
| Overall Risk Score | 50/100 | Moderate Risk |
| Provider Score | 0/100 | N/A |
| Authority Score | 0/100 | N/A |
| Stability Score | 0/100 | N/A |
| DNSBL Listings | 2/8 | Low |
| Operator Score | 0.2174 | Minimal |
---
## Threat Intelligence Findings
Direct Threat Indicators:
- No known attack campaigns detected
- Not identified as Tor exit node, known attacker, or spam source
- No open ports or active services detected (firewalled/no services)
- No TLS certificates or HTTP services
Indirect Threat Indicators:
- Subnet Abuse Density: 0.9336 (Critical - extremely high)
- Threat Siblings: 239 out of 256 IPs in /24 subnet classified as threats
- Neighborhood Risk: Inherited risk score of 37/100
- Risk Distribution: 100 medium-risk IPs, 0 high-risk IPs in sampled neighbors
Control Plane Observations:
- DNSSEC validation: Valid
- Route stability: Unstable
- RPKI state: Not evaluated
---
## Historical Observation Timeline
Total Observations: 46 signals across monitoring period
- Recent operator scores consistently show "Minimal" classification (raw score: 0.25)
- No persistent malicious behavior detected
- Threat persistence days: 0
- Single threat observation recorded
- Ownership changes: 0
---
## Relationship Graph
Connected Entities: 133 relationships detected
- Multiple "Same Network" relationships to LU-79 (Leaseweb network)
- Indicates extensive network-level connectivity
---
## Recommended Actions for SOC Analysts
Immediate Actions
1. Monitor, Do Not Block: The IP shows moderate risk with no direct malicious indicators. Blocking may impact legitimate traffic from a hosting provider.
2. Monitor Subnet Traffic: The /24 subnet exhibits critical abuse density. Implement rate limiting and traffic analysis for 173.234.227.0/24.
3. DNSBL Verification: Confirm the 2 DNSBL listings and evaluate their impact on email/reputation.
Defensive Recommendations
- Firewall Rules: No aggressive blocking required. Consider monitoring for unusual outbound connections from this IP.
- Traffic Analysis: Flag traffic from this subnet for deeper inspection during business hours.
- Email Reputation: Monitor email authentication (SPF/DMARC) from this IP if used for mail services.
Long-term Considerations
- Subnet-Level Mitigation: Consider implementing controls at the /24 or /22 level given the extreme neighborhood abuse density.
- Threat Intelligence Integration: Add 173.234.227.63 to monitoring lists as a "watchlist" IP pending neighborhood-level threat development.
---
Classification: Moderate Risk / Neighborhood Threat Present
Date: 2026-06-19
Data Sources: IPDebrief Intelligence Platform
Analyst Confidence: Medium (neighborhood data provides context; direct indicators limited)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 34% | 1 | 4 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 26% | 2 | 3 |
| Overall | 26% | 10 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:04 UTC |
| Last Seen | 2026-06-27 11:26:25 UTC |
| Profile Built | 2026-06-28 05:32:23 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 54 |
Full dossier details are available via our API.