Add filter rules in ip firewall input chain to drop all incoming DNS packets (TCP/UDP 53) from your WAN interfaces.
These domains contains lots of A and AAAA records. Some servers continuously send DNS queries of these domains all over the internet, I don't know the purpose...