Microsoft Edge is making Suspicious Connection?

Anonymous
2023-11-02T09:18:58+00:00

is Microsoft is making suspicious connection to this URL deff.nelreports.net/api/report?

Also let us know which data is being sent to this URL & When?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2023-11-15T15:40:03+00:00

*.nelreports.net is a Microsoft domain. Several certificates used on the subdomains of this domain expired last week.

There is no security impact or end-user-impact of the certificate expiration -- Basically, the browser will be unable to submit Network Error Logging reports until the certificate is corrected. Network Error Logging is a HTML5 feature to allow site owners to discover network connectivity problems. https://developer.mozilla.org/en-US/docs/Web/HTTP/Network\_Error\_Logging

Your security software is just announcing "Hey, this certificate is bad", a fact that the browser already was determining on its own, and to which it responds by not connecting to the server in question. The security software provides a redundant warning -- the browser will not use connections with expired or invalid certificates.

The subdomain names are random strings of characters with no particular meaning.

The relevant team has been notified about the certificate expiration and will correct the issue.

Was this answer helpful?

8 people found this answer helpful.
0 comments No comments

51 additional answers

Sort by: Oldest
  1. Anonymous
    2023-11-11T02:40:14+00:00

    Same thing here. I was forced to end Edge through the task manager, as it runs in the background and Bit Defender issues the same alerts. "Suspicious connection blocked."

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-11-11T02:49:44+00:00

    I had the same suspicious alert. Looks like it's a MSFT owned domain

    What on earth is MSFT doing? It's also an awfully suspicious domain name

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. _AW_ 69,496 Reputation points Volunteer Moderator
    2023-11-11T02:54:31+00:00

    It's a Microsoft registered domain -

    https://whois.domaintools.com/nelreports.net 

    I can't tell you exactly what the connection is, but possibly SmartScreen related + Azure DNS

    Report it to Bitdefender as a potential false positive.

    Incorrect Detection: Report a false positive or false negative to Bitdefender

    Was this answer helpful?

    9 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2023-11-11T03:47:07+00:00

    Here is an excellent VirusTotal report on it...

    https://www.virustotal.com/gui/domain/deff.nelreports.net/details deff.nelreports.net

    Looks like that is a Microsoft URL that is invoked by Edge & Internet Explorer. The Google search (at VirusTotal) finds your query to be fifth down from the top of "about 177". It isn't happening to me. Maybe you've got an old certificate, I don't know. But when I look for mine, I find no certificate, in Manage Computer Certificates (type certificates into Search)...

    Image

    It also appears not to be mentioned in my firewall in outgoing or incoming rules, at "Windows Security, Firewall & Network Protection, Advanced Settings". Also, on that page, it isn't mentioned in "Allow an app through firewall".

    I read through a couple of those 177 but haven't found a cure for you. Maybe I'll try again later.

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments