I use 1.1.1.2 and 1.0.0.2 as my DNS on my NetComm NF18MESH router.
I had CG-NAT disabled a few days ago for Xbox reasons.
I checked 1.1.1.1/help and majority of the time I’d get Cloudflare as the AS (AS Number 13335) from the SYD Data Centre
but after a few refreshes I did spot an AS PJSC MegaFon with AS Number 31163
and hours later an AS Robi with AS Number 24432, both stating they’re from the SYD Data Centre.
My concern is ‘is it ‘normal’ for a Russian and Bangladeshi ASN - or any other ‘random’ ASNs - to serve via the SYD Data Centre?’ or do I have an issue in my network? I’ve scanned devices with Windows Defender, Malwarebytes, and Sophos Intercept X for Mobile and they all say they’re clean. And my router doesn’t appear to have any random DNS servers - just the Cloudflare ones I used.
I did try /cdn-cgi/trace and it returned as SYD for the Colo. I’d have to be lucky to do it at the same time as I hit a random AS Name it seems.
Also: Apologies for not copying the URLs except for the Robi one; I thought I could Google Lens the URL from the screenshots but it copies the text wrong.