gvt2 domain connecting to Japan, Europe, Brazil… | by Teri Radichel | Cloud Security | Medium

See original article

Unusual Google Domain Connections

The author noticed their system connecting to various international locations (Japan, Europe, Brazil, etc.) through the domain e2c4.gcp.gvt2.com, a Google domain. This raised concerns as Google typically uses local connections for updates. Blocking geolocation on their laptop initially hid the connection but the issue resolved itself after blocking traffic to the Japanese location.

Global Connections

Further investigation revealed connections to multiple locations worldwide, including Switzerland, Paris, Brazil, Toronto, and several US locations.

Google's 'Beacons' and EdgeDL Subdomains

The author noted that Google uses 'beacons' subdomains, some resolving to expected locations (LA or San Jose), while others reported no location at all. Similarly, the edgedl subdomain under gvt1 (presumed Chrome download domain) didn't provide a location.

Unresolved Questions

Due to time constraints, the author couldn't fully investigate the purpose of these domains. They currently block connections to certain locations.

Sign up for a free account and get the following:
  • Save articles and sync them across your devices
  • Get a digest of the latest premium articles in your inbox twice a week, personalized to you (Coming soon).
  • Get access to our AI features