# IP Intelligence Briefing: 173.234.227.85/32
## Executive Summary
IP address 173.234.227.85 is hosted on Leaseweb USA, Inc. (ASN 394380) infrastructure in Dallas, TX, operating within a high-abuse density subnet. The IP exhibits moderate risk characteristics with 2 DNSBL listings and 0 open services, suggesting a dormant or blocked hosting environment.
## Network Classification
- Owner: Leaseweb USA, Inc.
- ASN: 394380
- Location: Dallas, TX, United States
- Infrastructure Type: Colocation Hosting (Choopa/GameServers provider)
- Service Status: Firewalled / No Services Detected
- DNSBL Status: Listed on 2 of 8 threat feeds
## Risk Assessment
| Metric | Value | Severity |
|---|---|---|
| Overall Risk Score | 50 | Moderate |
| Operator Score | 0.1304 | Minimal |
| Abuse Confidence | N/A | N/A |
| Threat Persistence | 0 days | Low |
| Is Known Attacker | No | - |
| Is Tor Exit | No | - |
| Is Proxy | No | - |
## Neighborhood Context (173.234.227.0/24)
- Abuse Density: 0.7969 (High)
- Subnet Classification: High Abuse
- Total Siblings: 256
- Active Siblings: 243 (95% utilization)
- Threat Siblings: 204 (80% of active IPs flagged)
- Inherited Risk Score: 31
The subnet exhibits elevated abuse characteristics with 204 of 256 sibling IPs flagged as threat sources. This contextualizes 173.234.227.85 within a high-risk hosting environment.
## Observation History
- Total Observations: 42 signals
- Recent Trend: Consistent "Minimal" operator scores across June 2026 observations
- Threat Persistence: 0 days (no persistent malicious activity detected)
- Campaign Correlation: None identified
Recent probes show stable minimal-risk behavior with no escalation in threat indicators.
## Relationship Graph
- Total Relationships: 140
- Network Associations: Multiple "Same Network" relationships (LU-79)
- Entity Type: Primarily network-level connections
## Technical Profile
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- Reverse DNS (PTR): None
- Forward Resolution: None
- Email Authentication: No SPF/DMARC records
- BGP Prefix: 173.234.227.0/24
- Route Stability: False (0 changes in 30 days)
- DNSSEC: Valid
## Recommended Actions
1. Monitor: Maintain observation for potential abuse pattern emergence
2. Contextualize: Treat as high-risk due to subnet abuse density (0.7969)
3. Block Criteria: Consider blocking if connected traffic shows suspicious patterns given 2 DNSBL listings
4. Investigate: Monitor for any service activation or port opening events
## Intelligence Assessment
This IP represents a dormant or blocked hosting resource within a high-abuse colocation environment. The combination of:
- Zero open services
- No active threat indicators
- Moderate risk score (50)
- High neighborhood abuse density
suggests the IP may be used for legitimate hosting with potential for abuse by third parties. SOC analysts should monitor for service activation or DNSBL list additions as indicators of abuse onset. The subnet's 80% threat sibling rate warrants elevated contextual awareness for all addresses within 173.234.227.0/24.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Leaseweb USA, Inc. |
| ASN | AS394380 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 45% | 1 | 6 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 27% | 10 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:05:04 UTC |
| Last Seen | 2026-06-27 11:30:06 UTC |
| Profile Built | 2026-06-28 05:36:54 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 49 |
Full dossier details are available via our API.