Why is the logfile full of source IPs which are mapped to the wrong countries?

2»

All Replies

  • Zyxel_USG_User
    Zyxel_USG_User Posts: 94  Ally Member
    First Answer First Comment Friend Collector First Anniversary

    Thanks for the update.

    Regarding the 87.120.222.229, check it up on malwareurl.com, scamalytics.com ,it is shown as being a commercial server proxying traffic from anywhere / elsewhere, and they show .bg as domain origin. Interesting.

  • Zyxel_USG_User
    Zyxel_USG_User Posts: 94  Ally Member
    First Answer First Comment Friend Collector First Anniversary

    I updated the GeoIP database to the latest today.

    Recent entry is shown in the log like this:

    image.png

    This one shows it as being from .uk:

    https://www.whois.com/whois/45.142.193.172

    This one shows .nl:

    https://www.shodan.io/host/45.142.193.172

    And this one, .de:

    https://whoisrequest.com/ip/45.142.193.172

    I guess, it depends who you ask then as well it may show it differently :)

    I am aware of proxying, VPNs etc.

    Can you then specify the most precise tool to query where the IP is from?