Not too much info from your side to work with…
That said, the most likely explanation is that Rspamd or Postscreen is making DNSBL (DNS blacklist) and URIBL lookups to check the sender’s IP reputation. Some obscure RBLs or spam domains may resolve to .ru TLDs or rely on Russian DNS servers.
A less likely, but not impossible explanation is that your server is somehow compromised or infected with malware.
By the way, are you sure it’s actually a service provided by Mailcow making the requests, and not some other service or container running on the server?