I use WHM dnsonly. The CSF firewall is installed and I see an IP address in the CSF TOP100 list blocked.

Time.....From..................Port.......I/O.. To........................ Port Proto
xx........ 77.56.56.444...58399...out...185.207.105.38...123...UDP
xx........ 77.56.56.444...47539...out...185.207.105.38...123...UDP
"From" is the IP of the WHM dnsonly Server, okay.... I see.....
And "Port" shows me the tested Port of my WHM dnsonly server..... good....
But HOW from this IP address is it possible to generate the OUTGOING Port 123 UDP ?
If I make an port scan on my main server for example, I em not able to generate this entries.
And I em not able to come to the idea of this strange unknowing IP address.... cause the main server have just an empty website on it right now....
Could anybody help me with an plausible answer, maybe I can't see the wood for the trees right now.

Time.....From..................Port.......I/O.. To........................ Port Proto
xx........ 77.56.56.444...58399...out...185.207.105.38...123...UDP
xx........ 77.56.56.444...47539...out...185.207.105.38...123...UDP
"From" is the IP of the WHM dnsonly Server, okay.... I see.....
And "Port" shows me the tested Port of my WHM dnsonly server..... good....
But HOW from this IP address is it possible to generate the OUTGOING Port 123 UDP ?
If I make an port scan on my main server for example, I em not able to generate this entries.
And I em not able to come to the idea of this strange unknowing IP address.... cause the main server have just an empty website on it right now....
Could anybody help me with an plausible answer, maybe I can't see the wood for the trees right now.