This is a known issue, where when are looking at NTLM events ATA is recording the name of the computer incorrectly.
MSTSC is not the name of the computer, it was just the name of the software mstsc.exe. we considered it as a computer because of the details we have in 4776 event.
Since it's not coming from network traffic, we don't have the source IP.
You can look at the event 4776 on the DC itself, but I am not sure if you will be able to see more data there,
I think we extract whatever we can from it already.