Bitdefender keeps blocking a suspicious connection every time I start Edge


zooburner

I really don't burn zoos !
Member
Local time
2:15 AM
Posts
87
OS
Windows 11 (Pro)
I keep getting this from bitdefender...

Feature:Online Threat Prevention
msedge.exe attempted to establish a connection relying on an expired certificate to bzib.nelreports.net. We blocked the connection to keep your data safe since websites must renew their certificates with a certification authority to stay current, and outdated security certificates represent a risk.


Firstly, I've never seen or heard of nelreports.net, secondly why is edge contacting it anyway?

I've done a full scan with Bitdefender, Defender, and a quick scan with Malwarebytes, nothing has turned up. Edge is set to open up on a blank page at start.
 

My Computer

System One

  • OS
    Windows 11 (Pro)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Scan Vengeance
    CPU
    i7 8700K
    Motherboard
    ROG Strix Z370F Gaming
    Memory
    16GB Corsair Vengeance
    Graphics Card(s)
    Nvidia 1070Ti
    Sound Card
    Onboard / Realtek
    Monitor(s) Displays
    BENQ GL2450
    Screen Resolution
    1920x1080
    Hard Drives
    1x Samsung 960 ProM=M.2 NVE 250GB
    1x Samsung SSD 860Pro SSD 250GB
    1x WD 2GB Spinner
    PSU
    Corsair 550w
    Case
    Fractual Mesh
    Cooling
    Corsair water cooling H100i v2
    Keyboard
    Microsoft keyboard and mouse combo
    Mouse
    Microsoft
    Browser
    Edge
    Antivirus
    Bitdefender
Are you a Windows Insider? Canary build? I am receiving the same flag. The site appears to be an Azure web app page. Bitdefender is also blocking deff.nelreports.net since the last update. I believe this is related to the news feed. check out this report --
bzib.nelreports.net is a subdomain of nelreports.net. DNS resolution of bzib.nelreports.net points to 23.195.105.139 with a location in Seattle, Washington US. Parent domain registration belongs to Microsoft Corporation, registered through CSC Corporate Domains, Inc.. The server responds with an SSL certificate issud by Microsoft Corporation to Microsoft Corporation under the common name *.nelreports.net.

Cloudflare security assessment status for nelreports.net: Safe ✅.
 

My Computer

System One

  • OS
    Windows 11 Pro Insider Preview 25992.1000
    Computer type
    PC/Desktop
    Manufacturer/Model
    DELL
    CPU
    Intel(R) Core (TM) i7-4770 CPU @ 3.40GHz 3.40 GHz
    Memory
    32.0 GB RAM
    Graphics Card(s)
    AMD Radeon (TM) R7 360 Series
    Monitor(s) Displays
    Seiki 40" and Dell 32"
    Screen Resolution
    2160p and 1080p
    Hard Drives
    Samsung 860 SSD 1 TB; Samsung 850 SSD 500 GB; Corsair SSD 240 GB; Seagate Enterprise HDD 8 TB; J Micron H/W Raid5 HDD 12 TB; Hitachi HDD 3 TB; WD Passport HDD 2 TB; Toshiba HDD 1 TB
    Keyboard
    Tecknet Gaming
    Mouse
    Tecknet Gaming
    Internet Speed
    900 GB
    Browser
    EDGE
    Antivirus
    Bitdefender; Windows Defender; Malwarebytes; Hitman Pro
No, I'm on the slow channel regarding builds, I don't even install the monthly preview updates.

What may be of interest is I have Chrome as the default browser and Edge nags to make it the default browser are getting bigger and bigger, last one was about a third of the window making it impossible to work without interacting with it.

It was after I refused that that I started getting the notifications from Bitdefender, and it now happens every time I open Edge.
 

My Computer

System One

  • OS
    Windows 11 (Pro)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Scan Vengeance
    CPU
    i7 8700K
    Motherboard
    ROG Strix Z370F Gaming
    Memory
    16GB Corsair Vengeance
    Graphics Card(s)
    Nvidia 1070Ti
    Sound Card
    Onboard / Realtek
    Monitor(s) Displays
    BENQ GL2450
    Screen Resolution
    1920x1080
    Hard Drives
    1x Samsung 960 ProM=M.2 NVE 250GB
    1x Samsung SSD 860Pro SSD 250GB
    1x WD 2GB Spinner
    PSU
    Corsair 550w
    Case
    Fractual Mesh
    Cooling
    Corsair water cooling H100i v2
    Keyboard
    Microsoft keyboard and mouse combo
    Mouse
    Microsoft
    Browser
    Edge
    Antivirus
    Bitdefender
This is the official whois record:

Domain Name: nelreports.net
Registry Domain ID: 2374329185_DOMAIN_NET-VRSN
Registrar WHOIS Server: whois.corporatedomains.com
Registrar URL: www.cscprotectsbrands.com
Updated Date: 2023-03-24T01:07:19Z
Creation Date: 2019-03-28T17:22:10Z
Registrar Registration Expiration Date: 2024-03-28T21:22:10Z
Registrar: CSC CORPORATE DOMAINS, INC.
Sponsoring Registrar IANA ID: 299
Registrar Abuse Contact Email: domainabuse@cscglobal.com
Registrar Abuse Contact Phone: +1.8887802723
Domain Status: clientTransferProhibited EPP Status Codes | What Do They Mean, and Why Should I Know? - ICANN
Registry Registrant ID:
Registrant Name: Domain Administrator
Registrant Organization: Microsoft Corporation
Registrant Street: One Microsoft Way
Registrant City: Redmond
Registrant State/Province: WA
Registrant Postal Code: 98052
Registrant Country: US
Registrant Phone: +1.4258828080
Registrant Phone Ext:
Registrant Fax: +1.4259367329
Registrant Fax Ext:
Registrant Email: domains@microsoft.com
Registry Admin ID:
Admin Name: Domain Administrator
Admin Organization: Microsoft Corporation
Admin Street: One Microsoft Way
Admin City: Redmond
Admin State/Province: WA
Admin Postal Code: 98052
Admin Country: US
Admin Phone: +1.4258828080
Admin Phone Ext:
Admin Fax: +1.4259367329
Admin Fax Ext:
Admin Email: domains@microsoft.com
Registry Tech ID:
Tech Name: MSN Hostmaster
Tech Organization: Microsoft Corporation
Tech Street: One Microsoft Way
Tech City: Redmond
Tech State/Province: WA
Tech Postal Code: 98052
Tech Country: US
Tech Phone: +1.4258828080
Tech Phone Ext:
Tech Fax: +1.4259367329
Tech Fax Ext:
Tech Email: msnhst@microsoft.com
Name Server: ns2-204.azure-dns.net
Name Server: ns4-204.azure-dns.info
Name Server: ns1-204.azure-dns.com
Name Server: ns3-204.azure-dns.org
DNSSEC: unsigned
URL of the ICANN WHOIS Data Problem Reporting System: Submitting a Complaint to ICANN Contractual Compliance - ICANN
>>> Last update of WHOIS database: 2023-03-24T01:07:19Z <<<
 

My Computer

System One

  • OS
    Windows XP/7/8/8.1/10/11, Linux, Android, FreeBSD Unix
    Computer type
    Laptop
    Manufacturer/Model
    Dell XPS 15 9570
    CPU
    Intel® Core™ i7-8750H 8th Gen Processor 2.2Ghz up to 4.1Ghz
    Motherboard
    Dell XPS 15 9570
    Memory
    32GB using 2x16GB modules
    Graphics Card(s)
    Intel UHD 630 & NVIDIA GeForce GTX 1050 Ti with 4GB DDR5
    Sound Card
    Realtek ALC3266-CG
    Monitor(s) Displays
    15.6" 4K Touch UltraHD 3840x2160 made by Sharp
    Screen Resolution
    3840x2160
    Hard Drives
    Toshiba KXG60ZNV1T02 NVMe 1024GB/1TB SSD
    PSU
    Dell XPS 15 9570
    Case
    Dell XPS 15 9570
    Cooling
    Stock
    Keyboard
    Stock
    Mouse
    SwitftPoint ProPoint
    Internet Speed
    Comcast/XFinity 1.44Gbps/42.5Mbps
    Browser
    Microsoft EDGE (Chromium based) & Google Chrome
    Antivirus
    Windows Defender that came with Windows
Aye, it's likely safe and part of some feedback set up by Microsoft. Bitdefender just does not seem to like the certificate for the domain (out of date perhaps), I'm inclined to ignore it for now.
 

My Computer

System One

  • OS
    Windows 11 (Pro)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Scan Vengeance
    CPU
    i7 8700K
    Motherboard
    ROG Strix Z370F Gaming
    Memory
    16GB Corsair Vengeance
    Graphics Card(s)
    Nvidia 1070Ti
    Sound Card
    Onboard / Realtek
    Monitor(s) Displays
    BENQ GL2450
    Screen Resolution
    1920x1080
    Hard Drives
    1x Samsung 960 ProM=M.2 NVE 250GB
    1x Samsung SSD 860Pro SSD 250GB
    1x WD 2GB Spinner
    PSU
    Corsair 550w
    Case
    Fractual Mesh
    Cooling
    Corsair water cooling H100i v2
    Keyboard
    Microsoft keyboard and mouse combo
    Mouse
    Microsoft
    Browser
    Edge
    Antivirus
    Bitdefender
Yes, it is Microsoft. We're getting hits from Edge trying to connect to Microsoft servers in the background (I believe). Both OP and I are on Insider Preview builds, but I'm not sure it's specifically an insider issue.
 

My Computer

System One

  • OS
    Windows 11 Pro Insider Preview 25992.1000
    Computer type
    PC/Desktop
    Manufacturer/Model
    DELL
    CPU
    Intel(R) Core (TM) i7-4770 CPU @ 3.40GHz 3.40 GHz
    Memory
    32.0 GB RAM
    Graphics Card(s)
    AMD Radeon (TM) R7 360 Series
    Monitor(s) Displays
    Seiki 40" and Dell 32"
    Screen Resolution
    2160p and 1080p
    Hard Drives
    Samsung 860 SSD 1 TB; Samsung 850 SSD 500 GB; Corsair SSD 240 GB; Seagate Enterprise HDD 8 TB; J Micron H/W Raid5 HDD 12 TB; Hitachi HDD 3 TB; WD Passport HDD 2 TB; Toshiba HDD 1 TB
    Keyboard
    Tecknet Gaming
    Mouse
    Tecknet Gaming
    Internet Speed
    900 GB
    Browser
    EDGE
    Antivirus
    Bitdefender; Windows Defender; Malwarebytes; Hitman Pro
Hey guys, is not related with insider, I have the same issue, on 4 different PCs. I contacted both microsoft and bitdefender support.

Microsoft didn't really answer my question to "why is a request I don't specifically make is being sent", but the agent said is a defunct service that doesn't need a certificate anymore. However... after I kept him on for like 1h I don't know if he only said that to get rid of me or he got some confirmation. I'm inclined to think he got some info during the chat (he seemed to genuinely try to help me) but can't be sure. He also said they sent a mail to bitdefender regarding this. But... I still don't think is fine. A bad certificate is a bad certificate, and if the endpoint is defunct they should just not call it. And more importantly... why the hell does my browser decide to do that call for me, without any kind of option to stop it (I tried to find one for hours).

I have no idea why they don't just make a public list with "hey, those are the stuff that our services call: edge startup -> nelreports.net because whatever". That way at least I have an official list, and I can safely add an exception. But this way... I just leave the block there and I get spammed every 20 seconds.

Bitdefender was even worse (support wise), since their "24/7 real human chat support" was a bot masquerading as a human (and not even doing it well... I got the bot experience with the response time of humans... great). All I got was "we will get back to you soon". However... I don't think is their fault.

So... anyway to get rid of this would be great. Since changing browsers does not work (because widgets for example still use edge behind). And trying to get rid of the request... I can't seem to find a way. Adding an exception without an official post also isn't a solution for me. I use those machines professionally. I can't just add exceptions without fully understanding why the request is made, by whom, why the cert is not renewed etc.

If you have any idea pls. post it... is annoying as hell.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
No, I'm on the slow channel regarding builds, I don't even install the monthly preview updates.

What may be of interest is I have Chrome as the default browser and Edge nags to make it the default browser are getting bigger and bigger, last one was about a third of the window making it impossible to work without interacting with it.

It was after I refused that that I started getting the notifications from Bitdefender, and it now happens every time I open Edge.



Personally, I just blocked msEdge.exe and microsoftedgeupdate.exe in Bitdefender's firewall.
Also, (I use Firefox)... there's a Firefox tweak that stops Edge from nagging (at least in Firefox).

In Bitdefender's firewall Settings > Default application behavior... I have it set to "Block", (outgoing connections).
On the firewall's Application Access tab... I can see what programs are trying to connect to the internet.
Then I can go onto the Rules tab, and allow them if I want.
 
Last edited:

My Computers

System One System Two

  • OS
    Win 11 Home ♦♦♦22631.3527 ♦♦♦♦♦♦♦23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 4702)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Internet Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Mouse
    Logitech Optical M-BT96a
    Keyboard
    Logitech Classic Keybooard 200
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 13 years?
Since no real solution was found that doesn't involve any kind of compromise I solved it like this:

I just created a static route for those 2 domains in my hosts file to redirect to local. And since local is not answering with anything... they are not blocked, they just fail. So I get rid of the spam, and I don't need to dig a security hole for some stupid random endpoint.

However... the whole situation is idiotic.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
I am going to leave it as it is. If Microsoft is too lazy to update the certificate then so be it. I always check BitDefender to see if it is a site I do not want blocked.
 

My Computer

System One

  • OS
    Windows 10
Since no real solution was found that doesn't involve any kind of compromise I solved it like this:

I just created a static route for those 2 domains in my hosts file to redirect to local. And since local is not answering with anything... they are not blocked, they just fail. So I get rid of the spam, and I don't need to dig a security hole for some stupid random endpoint.

However... the whole situation is idiotic.

Exactly, if it's not used anymore, simply remove Edge requesting the site.
 

My Computer

System One

  • OS
    Windows 11 (Pro)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Scan Vengeance
    CPU
    i7 8700K
    Motherboard
    ROG Strix Z370F Gaming
    Memory
    16GB Corsair Vengeance
    Graphics Card(s)
    Nvidia 1070Ti
    Sound Card
    Onboard / Realtek
    Monitor(s) Displays
    BENQ GL2450
    Screen Resolution
    1920x1080
    Hard Drives
    1x Samsung 960 ProM=M.2 NVE 250GB
    1x Samsung SSD 860Pro SSD 250GB
    1x WD 2GB Spinner
    PSU
    Corsair 550w
    Case
    Fractual Mesh
    Cooling
    Corsair water cooling H100i v2
    Keyboard
    Microsoft keyboard and mouse combo
    Mouse
    Microsoft
    Browser
    Edge
    Antivirus
    Bitdefender
Search for News App in your search toolbar, click on the News App and it should automatically update to the latest version. Then all is good.
 

My Computer

System One

  • OS
    Windows 11
The certificate should last a year, so this is a strange config (misconfig), my guess is that it will renewed automatically within 5 days.

capture_11112023_154630.jpg

By the way I am accustomed to Edge spamming, I use DoH, yet it desperately tries to connect to somewhere. :look:

capture_11112023_155047.jpg

P.S. I have blocked Bing/MSN, so maybe it just tries to phone home.

th-2772547176 (2).jpg
 
Last edited:

My Computer

System One

  • OS
    Windows 11 Home
    Computer type
    PC/Desktop
    CPU
    AMD Ryzen 5 3600 & No fTPM (07/19)
    Motherboard
    MSI B450 TOMAHAWK 7C02v1E & IFX TPM (07/19)
    Memory
    4x 8GB ADATA XPG GAMMIX D10 DDR4 3200MHz CL16
    Graphics Card(s)
    MSI Radeon RX 580 ARMOR 8G OC @48FPS (08/19)
    Sound Card
    Creative Sound Blaster Z (11/16)
    Monitor(s) Displays
    24" AOC G2460VQ6 (01/19)
    Screen Resolution
    1920×1080@75Hz & FreeSync (DisplayPort)
    Hard Drives
    ADATA XPG GAMMIX S11 Pro SSD 512GB (07/19)
    PSU
    Seasonic M12II-520 80 Plus Bronze (11/16)
    Case
    Lian Li PC-7NB & 3x Noctua NF-S12A FLX@700rpm (11/16)
    Cooling
    CPU Cooler Noctua NH-U12S@700rpm (07/19)
    Keyboard
    HP Wired Desktop 320K + Rabalux 76017 Parker (01/24)
    Mouse
    Logitech M330 Silent Plus (04/23)
    Internet Speed
    400/40 Mbps via RouterOS (05/21) & TCP Optimizer
    Browser
    Edge (No FB/Google) & Brave for YouTube & LibreWolf for FB
    Antivirus
    NoAV & Binisoft WFC & NextDNS
    Other Info
    Headphones: Sennheiser RS170 (09/10)
    Phone: Samsung Galaxy Xcover 7 (02/24)
Back
Top Bottom