Now it’s pretty clear, I am mistaken for a malicious site (probably because many different computers in the lab started to exchange data with this obscure freedns subdomain) by this software from Palo Alto Networks gavstech.com/palo-alto-firewall-dns-sinkhole/ which rewrites the DNS response