Good evening. I'm having a little bit of confusion with some of the data on my firewall.
In the GUI, it shows an attempted connection from the source 193.37.69.203 over port 3389 with a Russian Federation flag.
There are two things I found a bit confusing.
1.) One of my analysts colleagues at markup related to that IP, and it reads as:
"ip": 193.37.69.203
"country_name": Netherlands.
2.) Looking up the IP in arin.net, shows it as having a registration in London.
https://search.arin.net/rdap/?query=193.37.69.203
Can anyone tell me what might be the source of the inconsistency? One thing we did look at was the IP in RiskIQ, and it appears that a few Russian Federation related URLs are associated with it, so I'm not sure if I'm not understanding what goes into the data that we're being presented.
Thank you!