WAN IP is showing up as Botnet

Hey everyone, can anyone please help me understand how can the IP address of the WAN interface show up as Botnet in AppFlow report.

Category: Firewall Management and Analytics
