Google Widevine is a DRM system from Google and is used for rights management. The service can be found in chromium-based applications such as Steam, Microsoft Edge Browser, Chrome Browser, but also on video platforms such as YouTube or Amazon Prime.
GVT (Google Video Transcoding) connections stand for Google's non-transparent update service in relation to chromium applications, extensions and plugins such as WidevineDRM which are required for protected media files. Starting from the redirector.gvt1.com, reference is made to the actual address. The example shows the IP address 185.236.202.91 (here NordVPN) of the user together with the Unix time stamp (1638876621 - > Tue Dec 07 2021 11:30:21).
Content managed by Widevide also includes advertising videos and ads, depending on the service provider, as well as a separate function of the IP capture of users.
https://redirector.gvt1.com/edgedl/widevine-cdm/4.10.2209.1-win-x64.zip
<HTML>
<HEAD>
<meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved<</TITLE>
</HEAD>
<BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="https://r3---sn-n02xgoxufvg3-8pxe.gvt1.com/edgedl/widevine-cdm/4.10.2209.1-win-x64.zip?cms_redirect=yes&mh=hC&mip=185.236.202.91&mm=28&mn=sn-n02xgoxufvg3-8pxe&ms=nvh&mt=1638876621&mv=u&mvi=3&pl=24&rmhost=r2---sn-n02xgoxufvg3-8pxe.gvt1.com&shardbypass=yes">here</A>.
</BODY>
</HTML>
Destination
https://r3---sn-n02xgoxufvg3-8pxe.gvt1.com/edgedl/widevine-cdm/4.10.2209.1-win-x64.zip?cms_redirect=yes&mh=hC&mip=185.236.202.91&mm=28&mn=sn-n02xgoxufvg3-8pxe&ms=nvh&mt=1638876621&mv=u&mvi=3&pl=24&rmhost=r2---sn-n02xgoxufvg3-8pxe.gvt1.com&shardbypass=yes
https://redirector.gvt1.com/edgedl/widevine-cdm/versions.txt # Aufruf mit sofortiger Umleitung
<HTML>
<HEAD>
<meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved<</TITLE>
</HEAD>
<BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="https://r5---sn-5hne6nsy.gvt1.com/edgedl/widevine-cdm/versions.txt?cms_redirect=yes&mh=GP&mip=185.236.202.91&mm=28&mn=sn-5hne6nsy&ms=nvh&mt=1639074738&mv=m&mvi=5&pl=24&rmhost=r2---sn-5hne6nsy.gvt1.com&shardbypass=yes&smhost=r2---sn-5hne6nz6.gvt1.com">">here</A>.
</BODY>
</HTML>
Destination
https://r5---sn-5hne6nsy.gvt1.com/edgedl/widevine-cdm/versions.txt?cms_redirect=yes&mh=GP&mip=185.236.202.91&mm=28&mn=sn-5hne6nsy&ms=nvh&mt=1639074738&mv=m&mvi=5&pl=24&rmhost=r2---sn-5hne6nsy.gvt1.com&shardbypass=yes&smhost=r2---sn-5hne6nz6.gvt1.com
Callback with immediate forwarding
https://redirector.gvt1.com/videoplayback/id/fa8484d624b4d6c6/itag/46/source/dclk_video_ads/requiressl/yes/acao/yes/mime/video%2Fwebm/ctier/L/ip/0.0.0.0/ipbits/0/expire/1639148795/sparams/ip,ipbits,expire,id,itag,source,requiressl,acao,mime,ctier/signature/3C171CD9C02EFFA35DECB475F53781B7B30F0A9E.213781E0E7A823FD646A671E204093B1D7C5FB50/key/ck2/file/file.webm
Destination
https://r4---sn-4g5ednse.gvt1.com/videoplayback/id/fa8484d624b4d6c6/itag/46/source/dclk_video_ads/requiressl/yes/acao/yes/mime/video%2Fwebm/ctier/L/ip/0.0.0.0/ipbits/0/expire/1639148795/sparams/acao,ctier,expire,id,ip,ipbits,itag,mh,mime,mip,mm,mn,ms,mv,mvi,pl,requiressl,source/signature/0F23F334466F75738A801610BADBC70E00DB865A.4D425CEC0339163C2749AAF6194FBD580529F981/key/cms1/cms_redirect/yes/mh/Rb/mip/185.236.202.91/mm/28/mn/sn-4g5ednse/ms/nvh/mt/1639126591/mv/u/mvi/4/pl/27/file/file.webm
ams17s13-in-f9.1e100.net
beacons.gcp.gvt2.com
fra16s51-in-f14.1e100.net
r1---sn-4g5edn6r.gvt1.com
r1---sn-4g5edns7.gvt1.com
r1---sn-uxaxufv-uaae.gvt1.com
r1.sn-4g5lznes.gvt1.com
r1.sn-npoeenll.gvt1.com
r2---sn-4g5e6nzz.gvt1.com
r2---sn-4g5lzned.gvt1.com
r2---sn-5go7yner.gvt1.com
r2---sn-5hne6nzs.gvt1.com
r2---sn-aigl6ned.gvt1.com
r2.sn-4g5lznl6.gvt1.com
r2.sn-n4v7sn7y.gvt1.com
r3---sn-a5meknzr.gvt1.com
r3---sn-a5msen7l.gvt1.com
r3---sn-axq7sn76.gvt1.com
r3---sn-axq7sn7e.gvt1.com
r3---sn-uxaxufv-uaae.gvt1.com
r4---sn-4g5ednse.gvt1.com
r4---sn-axq7sn7z.gvt1.com
r4.sn-4g5lznlz.gvt1.com
r4.sn-oguesnz6.gvt1.com
r5---sn-4g5edn6k.gvt1.com
r5---sn-4g5edn7y.gvt1.com
r5---sn-4g5edne6.gvt1.com
r5---sn-4g5ednsr.gvt1.com
r5.sn-h0jeen76.gvt1.com
r6---sn-ab5szn76.gvt1.com
redirector.gvt1.com