# IP Intelligence Briefing: 173.234.227.8/32
Classification: Moderate Risk - Colocation Hosting Environment
Date: 2026-06-19
Risk Score: 50/100
## Ownership & Geolocation
- ASN: 394380 (Leaseweb USA, Inc.)
- Organization: Leaseweb USA, Inc.
- Location: Dallas, TX, US
- Network Role: Choopa/GameServers, Colocation Hosting Provider
- Infrastructure Type: Hosting/Colocation
## Threat Profile
- Risk Classification: Moderate Risk
- DNSBL Listings: 2 of 8 blacklist sources
- Open Ports: None detected (Firewalled/No Services)
- Known Threats: No active threat indicators
- Tor/Proxy: Not identified as Tor exit node, proxy, or VPN
## Neighborhood Analysis
- Subnet: 173.234.227.0/24
- Abuse Density: 0.9336 (High Abuse Classification)
- Threat Siblings: 239 out of 256 IPs flagged as threats
- Inherited Risk Score: 37/100
- Network Context: Environment shows significant abuse concentration consistent with game server colocation hosting
## Observation History
- Total Observations: 52 signals recorded
- Route Stability: Consistent (stable BGP routing)
- Recent Activity: Multiple observations from June 2026 showing consistent operator score of 0.4783
- Threat Persistence: 0 days (not persistently malicious)
## Relationships
- Connected Entities: 133 relationships identified
- Primary Network: LU-79 (same network associations)
- Infrastructure: Colocation hosting environment with multiple peer connections
## Recommended Actions
Firewall blocking is recommended for this IP address based on risk profile and neighborhood abuse density:
- iptables: `iptables -A INPUT -s 173.234.227.8 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 173.234.227.8 drop`
- nginx: `deny 173.234.227.8;`
- pfSense: Block 173.234.227.8/32
- Cloudflare WAF: Block with expression `ip.src eq 173.234.227.8`
- AWS WAF: Add 173.234.227.8/32 to blocklist
## SOC Analyst Notes
This IP resides within a high-abuse colocation hosting environment (Choopa/GameServers) operated by Leaseweb USA. The subnet demonstrates elevated abuse density with 239 threat-identified sibling IPs. While this specific IP shows no active services and no current threat indicators, the neighborhood context warrants defensive blocking. The IP's moderate risk score (50) combined with DNSBL listings suggests potential for abuse or spam activity. Monitor for any service activation on this IP address.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | 173.234.227.0/24 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 5 |
| routing | 48% | 2 | 7 |
| services | 20% | 2 | 3 |
| ownership | 24% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 32% | 12 | 25 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:04 UTC |
| Last Seen | 2026-06-27 11:17:11 UTC |
| Profile Built | 2026-06-28 05:22:01 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 61 |
Full dossier details are available via our API.