Unexpected blocked sites after installation

Hello,

I've installed PiHole on 2 Raspberry Pi, to have redundancy. Each Pi has several services in it. After installation, and without configuring any device to use them as DNS servers, I've seen already several DNS queries blocked:
On Pi #1:

ar.mytrack.pro
fengshangtp.net

On Pi #2:

stats.defense.gov
grey.soju.openx.net
text-confirm.xyz
eithertogether.net

How do I find where these queries came from?
Should I be worried about this?

You probably have port 53 open to the world and are currently being used to attack other DNS servers.

In fact the PiHole on Pi #2 is opened to the internet (I need to figure out how to disable it without disabling access to Nextcloud), but I don't port 53 forwarded in the router.
Any idea how to verify this?

Don't give public access to Pi-hole. Don't run it on a device that has public access.

True. But PiHole #1 is not visible from the internet. So I though it could be some software already installed on it.

Well, you're seeing queries that you don't know the source of. Draw your own conclusions.