Why is the logfile full of source IPs which are mapped to the wrong countries?
All Replies
-
Thanks for the update.
Regarding the 87.120.222.229, check it up on malwareurl.com, scamalytics.com ,it is shown as being a commercial server proxying traffic from anywhere / elsewhere, and they show .bg as domain origin. Interesting.
0 -
I updated the GeoIP database to the latest today.
Recent entry is shown in the log like this:
This one shows it as being from .uk:
This one shows .nl:
https://www.shodan.io/host/45.142.193.172
And this one, .de:
https://whoisrequest.com/ip/45.142.193.172
I guess, it depends who you ask then as well it may show it differently :)
I am aware of proxying, VPNs etc.
Can you then specify the most precise tool to query where the IP is from?
0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 199 Nebula Ideas
- 125 Nebula Status and Incidents
- 6.3K Security
- 492 USG FLEX H Series
- 322 Security Ideas
- 1.6K Switch
- 83 Switch Ideas
- 1.3K Wireless
- 47 Wireless Ideas
- 6.8K Consumer Product
- 285 Service & License
- 455 News and Release
- 89 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 95 Security Highlight
Ally Member