Onlyfun still don't get the origin and purpose of this ANDROID.
ANDROID is uid 0. When Rethink asks the ConnectivityManager (basically, the OS) for the "owner" of a particular (TCP/UDP) socket, it sometimes responds with 0 (which is shown as ANDROID in Rethink's network/dns logs).
It is blocked, still it has some connections listed, some of those are sites genuinely opened in Vanadium, others look related to the ones visited.
It could be that the OS attributed sockets opened by Vanadium to itself. That's a bug in the OS?
Why there is site 'x' in it's connections, but not site 'y'.
As before, Rethink shows you whatever the OS is reporting to it. It has no ability on its own otherwise to find the "owner".
After blocking all domains and ips on ANDROID page nothing changed, sites are still opening in Vanadium.
You must set rules for Vanadium and not ANDROID. Although, I get that if Vanadium sockets are incorrectly marked as being owned by ANDROID, the sites that should have been otherwise blocked will open. In that case, you can either set rules for both ANDROID (does Rethink allow this?) + Vanadium, or completely block ANDROID (although, I don't recommend it), or block domains / IP at "Universal" (global) level from Configure -> Firewall -> IP & Port rules).