Pihole malware alert

I am a novice PiHole user. Set one up as a DNS server for my home network which is a Unifi Dream Machine router. Upon installation I started getting messages from the UDM IPS that the pihole device is attempting potentially bad traffic to 9.9.9.9:53 ET DNS Query for .su TLD (Soviet Union) Often Malware Related. Interestingly, PiHole is configured to us cloudflare, 1.1.1.1. and not quad 9. I cannot link activity in PiHole logs to the UDM IPS alerts. Anyone out there have an ideas what this is all about?