Edit tour

Windows Analysis Report
https://east-rifle-cc2.notion.site/Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=4

Overview

General Information

Sample URL:https://east-rifle-cc2.notion.site/Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=4
Analysis ID:1670978
Infos:

Detection

Score:0
Range:0 - 100
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w11x64_office
  • chrome.exe (PID: 1780 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: DBE43C1D0092437B88CFF7BD9ABC336C)
    • chrome.exe (PID: 3472 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1996,i,10975350230579627962,12600055534810953432,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250316-180048.776000 --mojo-platform-channel-handle=2104 /prefetch:11 MD5: DBE43C1D0092437B88CFF7BD9ABC336C)
  • chrome.exe (PID: 6412 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://east-rifle-cc2.notion.site/Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=4" MD5: DBE43C1D0092437B88CFF7BD9ABC336C)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://east-rifle-cc2.notion.site/Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=4HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.24:60832 version: TLS 1.2
Source: unknownHTTPS traffic detected: 208.103.161.32:443 -> 192.168.2.24:60835 version: TLS 1.2
Source: unknownHTTPS traffic detected: 208.103.161.32:443 -> 192.168.2.24:60836 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.66
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=4 HTTP/1.1Host: east-rifle-cc2.notion.siteConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: east-rifle-cc2.notion.siteConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://east-rifle-cc2.notion.site/Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=4Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: notion_browser_id=585ef809-4eda-4365-9fac-07de7b4d7ba0; device_id=1ddd872b-594c-819b-aa35-003bd2a820d8; notion_check_cookie_consent=false
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: east-rifle-cc2.notion.site
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 22 Apr 2025 11:08:33 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeCF-Ray: 9344a9f2287b1dc2-PHXCF-Cache-Status: DYNAMICCache-Control: no-store, no-cache, must-revalidate, proxy-revalidateExpires: 0Last-Modified: Tue, 22 Apr 2025 09:51:10 GMTSet-Cookie: notion_browser_id=585ef809-4eda-4365-9fac-07de7b4d7ba0; Domain=east-rifle-cc2.notion.site; Path=/; Expires=Wed, 22 Apr 2026 11:08:33 GMT; SecureStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadVary: Accept-EncodingPragma: no-cache
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 22 Apr 2025 11:08:33 GMTContent-Type: application/json; charset=utf-8Content-Length: 28Connection: closeCF-Ray: 9344a9f66e6b720e-PHXCF-Cache-Status: HITAge: 192ETag: W/"1c-rse+oIWWZjJFS4zo55aR8QTCsdg"Strict-Transport-Security: max-age=31536000; includeSubDomains; preloadVary: Accept-Encoding
Source: unknownNetwork traffic detected: HTTP traffic on port 60849 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60817
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60849
Source: unknownNetwork traffic detected: HTTP traffic on port 60817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 60835 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 60836 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 60832 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60836
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60835
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60832
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.24:60832 version: TLS 1.2
Source: unknownHTTPS traffic detected: 208.103.161.32:443 -> 192.168.2.24:60835 version: TLS 1.2
Source: unknownHTTPS traffic detected: 208.103.161.32:443 -> 192.168.2.24:60836 version: TLS 1.2
Source: classification engineClassification label: clean0.win@21/2@4/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1996,i,10975350230579627962,12600055534810953432,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250316-180048.776000 --mojo-platform-channel-handle=2104 /prefetch:11
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://east-rifle-cc2.notion.site/Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=4"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1996,i,10975350230579627962,12600055534810953432,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250316-180048.776000 --mojo-platform-channel-handle=2104 /prefetch:11Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1670978 URL: https://east-rifle-cc2.noti... Startdate: 22/04/2025 Architecture: WINDOWS Score: 0 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.24, 137, 443, 49390 unknown unknown 5->13 10 chrome.exe 5->10         started        process4 dnsIp5 15 east-rifle-cc2.notion.site 208.103.161.32, 443, 60835, 60836 SNAGAJOBUS United States 10->15 17 www.google.com 142.250.69.4, 443, 60832, 60849 GOOGLEUS United States 10->17

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://east-rifle-cc2.notion.site/Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=40%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://east-rifle-cc2.notion.site/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.69.4
truefalse
    high
    east-rifle-cc2.notion.site
    208.103.161.32
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://east-rifle-cc2.notion.site/Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=4false
        unknown
        https://east-rifle-cc2.notion.site/favicon.icofalse
        • Avira URL Cloud: safe
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        142.250.69.4
        www.google.comUnited States
        15169GOOGLEUSfalse
        208.103.161.32
        east-rifle-cc2.notion.siteUnited States
        394835SNAGAJOBUSfalse
        IP
        192.168.2.24
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1670978
        Start date and time:2025-04-22 13:07:28 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 53s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://east-rifle-cc2.notion.site/Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=4
        Analysis system description:Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09
        Run name:Potential for more IOCs and behavior
        Number of analysed new started processes analysed:15
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:CLEAN
        Classification:clean0.win@21/2@4/3
        • Exclude process from analysis (whitelisted): SystemSettingsBroker.exe, SIHClient.exe, appidcertstorecheck.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 142.250.68.227, 142.250.69.14, 142.251.2.84, 199.232.214.172, 192.178.49.170, 192.178.49.202, 142.250.69.10, 142.250.68.234, 192.178.49.195, 199.232.210.172, 184.29.183.29, 4.175.87.197, 4.245.163.56
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, www.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com, c.pki.goog
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtOpenFile calls found.
        • VT rate limit hit for: https://east-rifle-cc2.notion.site/Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=4
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:JSON data
        Category:downloaded
        Size (bytes):28
        Entropy (8bit):4.066108939837481
        Encrypted:false
        SSDEEP:3:YIzDIwexY:YI3IwexY
        MD5:51E5E1C1DE8270ED97825FCB1C860A21
        SHA1:AEC7BEA085966632454B8CE8E79691F104C2B1D8
        SHA-256:42AB2C45AB6F9DC749C112B7BB3DCACC8A2464F661E28FC8D9006D8E31593F32
        SHA-512:14B6A068423D537F75D8D947BBCDDF9BB59F33037F62EBA69D16C99FA35A24111E884EC90912F3E2902813B6EC4A0F31DB05D67A34491FC297DDC4A912E6D436
        Malicious:false
        Reputation:low
        URL:https://east-rifle-cc2.notion.site/favicon.ico
        Preview:{"message":"File not found"}
        No static file info

        Download Network PCAP: filteredfull

        • Total Packets: 57
        • 443 (HTTPS)
        • 53 (DNS)
        TimestampSource PortDest PortSource IPDest IP
        Apr 22, 2025 13:08:31.432888031 CEST60832443192.168.2.24142.250.69.4
        Apr 22, 2025 13:08:31.432928085 CEST44360832142.250.69.4192.168.2.24
        Apr 22, 2025 13:08:31.433017015 CEST60832443192.168.2.24142.250.69.4
        Apr 22, 2025 13:08:31.433208942 CEST60832443192.168.2.24142.250.69.4
        Apr 22, 2025 13:08:31.433222055 CEST44360832142.250.69.4192.168.2.24
        Apr 22, 2025 13:08:31.751702070 CEST44360832142.250.69.4192.168.2.24
        Apr 22, 2025 13:08:31.751817942 CEST60832443192.168.2.24142.250.69.4
        Apr 22, 2025 13:08:31.752913952 CEST60832443192.168.2.24142.250.69.4
        Apr 22, 2025 13:08:31.752919912 CEST44360832142.250.69.4192.168.2.24
        Apr 22, 2025 13:08:31.753112078 CEST44360832142.250.69.4192.168.2.24
        Apr 22, 2025 13:08:31.806427956 CEST60832443192.168.2.24142.250.69.4
        Apr 22, 2025 13:08:32.452267885 CEST60835443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:32.452308893 CEST44360835208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:32.452378035 CEST60835443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:32.452629089 CEST60836443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:32.452641010 CEST44360836208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:32.452697039 CEST60836443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:32.452766895 CEST60835443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:32.452780962 CEST44360835208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:32.452929020 CEST60836443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:32.452940941 CEST44360836208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:32.742026091 CEST44360835208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:32.742091894 CEST60835443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:32.746902943 CEST44360836208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:32.746969938 CEST60836443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:32.748898029 CEST60835443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:32.748914003 CEST44360835208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:32.749124050 CEST44360835208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:32.749496937 CEST60836443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:32.749501944 CEST44360836208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:32.749754906 CEST60835443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:32.749830961 CEST44360836208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:32.789726019 CEST60836443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:32.792284966 CEST44360835208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:33.180883884 CEST44360835208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:33.180970907 CEST44360835208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:33.181030035 CEST60835443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:33.181052923 CEST44360835208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:33.181093931 CEST60835443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:33.181099892 CEST44360835208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:33.181305885 CEST44360835208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:33.181348085 CEST60835443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:33.181353092 CEST44360835208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:33.181710005 CEST44360835208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:33.181762934 CEST60835443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:33.188664913 CEST60835443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:33.188679934 CEST44360835208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:33.597707987 CEST60836443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:33.644274950 CEST44360836208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:33.754249096 CEST44360836208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:33.754365921 CEST44360836208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:33.754405975 CEST44360836208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:33.754425049 CEST44360836208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:33.754443884 CEST60836443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:33.754547119 CEST60836443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:33.758172989 CEST60836443192.168.2.24208.103.161.32
        Apr 22, 2025 13:08:33.758194923 CEST44360836208.103.161.32192.168.2.24
        Apr 22, 2025 13:08:39.605827093 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:39.605927944 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:39.605927944 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:39.884723902 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:39.884749889 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:39.884761095 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:40.132539034 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:40.132596016 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:40.133469105 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:40.133486986 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:40.133517981 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:40.133528948 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:40.156024933 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:40.170330048 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:40.435013056 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:40.449244022 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:40.455133915 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:40.455183029 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:40.456234932 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:40.456250906 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:40.456278086 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:40.456304073 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:40.468504906 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:40.468699932 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:40.734158039 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:40.734172106 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:40.734217882 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:40.734237909 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:40.740175009 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:40.740186930 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:40.740246058 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:40.742321968 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:41.061722040 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:41.065049887 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:41.065268040 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:41.065983057 CEST443608172.19.122.66192.168.2.24
        Apr 22, 2025 13:08:41.066054106 CEST60817443192.168.2.242.19.122.66
        Apr 22, 2025 13:08:41.750294924 CEST44360832142.250.69.4192.168.2.24
        Apr 22, 2025 13:08:41.750353098 CEST44360832142.250.69.4192.168.2.24
        Apr 22, 2025 13:08:41.750406981 CEST60832443192.168.2.24142.250.69.4
        Apr 22, 2025 13:08:42.266045094 CEST60832443192.168.2.24142.250.69.4
        Apr 22, 2025 13:08:42.266072989 CEST44360832142.250.69.4192.168.2.24
        Apr 22, 2025 13:09:31.353169918 CEST60849443192.168.2.24142.250.69.4
        Apr 22, 2025 13:09:31.353216887 CEST44360849142.250.69.4192.168.2.24
        Apr 22, 2025 13:09:31.353311062 CEST60849443192.168.2.24142.250.69.4
        Apr 22, 2025 13:09:31.353456974 CEST60849443192.168.2.24142.250.69.4
        Apr 22, 2025 13:09:31.353465080 CEST44360849142.250.69.4192.168.2.24
        Apr 22, 2025 13:09:31.666085005 CEST44360849142.250.69.4192.168.2.24
        Apr 22, 2025 13:09:31.666444063 CEST60849443192.168.2.24142.250.69.4
        Apr 22, 2025 13:09:31.666471958 CEST44360849142.250.69.4192.168.2.24
        Apr 22, 2025 13:09:41.668693066 CEST44360849142.250.69.4192.168.2.24
        Apr 22, 2025 13:09:41.668742895 CEST44360849142.250.69.4192.168.2.24
        Apr 22, 2025 13:09:41.668806076 CEST60849443192.168.2.24142.250.69.4
        Apr 22, 2025 13:09:42.275846004 CEST60849443192.168.2.24142.250.69.4
        Apr 22, 2025 13:09:42.275868893 CEST44360849142.250.69.4192.168.2.24
        TimestampSource PortDest PortSource IPDest IP
        Apr 22, 2025 13:08:27.061499119 CEST53493901.1.1.1192.168.2.24
        Apr 22, 2025 13:08:27.116419077 CEST53606531.1.1.1192.168.2.24
        Apr 22, 2025 13:08:28.229568958 CEST53623771.1.1.1192.168.2.24
        Apr 22, 2025 13:08:31.291563034 CEST5619753192.168.2.241.1.1.1
        Apr 22, 2025 13:08:31.291841984 CEST5814053192.168.2.241.1.1.1
        Apr 22, 2025 13:08:31.431740046 CEST53561971.1.1.1192.168.2.24
        Apr 22, 2025 13:08:31.431826115 CEST53581401.1.1.1192.168.2.24
        Apr 22, 2025 13:08:32.296298027 CEST5200053192.168.2.241.1.1.1
        Apr 22, 2025 13:08:32.296447992 CEST5894053192.168.2.241.1.1.1
        Apr 22, 2025 13:08:32.451247931 CEST53520001.1.1.1192.168.2.24
        Apr 22, 2025 13:08:32.451416969 CEST53589401.1.1.1192.168.2.24
        Apr 22, 2025 13:08:45.305445910 CEST53547741.1.1.1192.168.2.24
        Apr 22, 2025 13:08:55.171993017 CEST137137192.168.2.24192.168.2.255
        Apr 22, 2025 13:08:55.929596901 CEST137137192.168.2.24192.168.2.255
        Apr 22, 2025 13:08:56.411168098 CEST53579951.1.1.1192.168.2.24
        Apr 22, 2025 13:08:56.679666042 CEST137137192.168.2.24192.168.2.255
        Apr 22, 2025 13:09:04.106143951 CEST53628961.1.1.1192.168.2.24
        Apr 22, 2025 13:09:26.398890972 CEST53590891.1.1.1192.168.2.24
        Apr 22, 2025 13:09:26.777453899 CEST53547651.1.1.1192.168.2.24
        Apr 22, 2025 13:09:29.993489981 CEST53585631.1.1.1192.168.2.24
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Apr 22, 2025 13:08:31.291563034 CEST192.168.2.241.1.1.10x2559Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Apr 22, 2025 13:08:31.291841984 CEST192.168.2.241.1.1.10xebaaStandard query (0)www.google.com65IN (0x0001)false
        Apr 22, 2025 13:08:32.296298027 CEST192.168.2.241.1.1.10x29f1Standard query (0)east-rifle-cc2.notion.siteA (IP address)IN (0x0001)false
        Apr 22, 2025 13:08:32.296447992 CEST192.168.2.241.1.1.10xdd9fStandard query (0)east-rifle-cc2.notion.site65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Apr 22, 2025 13:08:31.431740046 CEST1.1.1.1192.168.2.240x2559No error (0)www.google.com142.250.69.4A (IP address)IN (0x0001)false
        Apr 22, 2025 13:08:31.431826115 CEST1.1.1.1192.168.2.240xebaaNo error (0)www.google.com65IN (0x0001)false
        Apr 22, 2025 13:08:32.451247931 CEST1.1.1.1192.168.2.240x29f1No error (0)east-rifle-cc2.notion.site208.103.161.32A (IP address)IN (0x0001)false
        Apr 22, 2025 13:08:32.451247931 CEST1.1.1.1192.168.2.240x29f1No error (0)east-rifle-cc2.notion.site208.103.161.33A (IP address)IN (0x0001)false
        Apr 22, 2025 13:08:32.451416969 CEST1.1.1.1192.168.2.240xdd9fNo error (0)east-rifle-cc2.notion.site65IN (0x0001)false
        • east-rifle-cc2.notion.site
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.2460835208.103.161.324433472C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-04-22 11:08:32 UTC743OUTGET /Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=4 HTTP/1.1
        Host: east-rifle-cc2.notion.site
        Connection: keep-alive
        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9
        2025-04-22 11:08:33 UTC604INHTTP/1.1 404 Not Found
        Date: Tue, 22 Apr 2025 11:08:33 GMT
        Content-Type: text/html; charset=utf-8
        Transfer-Encoding: chunked
        Connection: close
        CF-Ray: 9344a9f2287b1dc2-PHX
        CF-Cache-Status: DYNAMIC
        Cache-Control: no-store, no-cache, must-revalidate, proxy-revalidate
        Expires: 0
        Last-Modified: Tue, 22 Apr 2025 09:51:10 GMT
        Set-Cookie: notion_browser_id=585ef809-4eda-4365-9fac-07de7b4d7ba0; Domain=east-rifle-cc2.notion.site; Path=/; Expires=Wed, 22 Apr 2026 11:08:33 GMT; Secure
        Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
        Vary: Accept-Encoding
        Pragma: no-cache
        2025-04-22 11:08:33 UTC6220INData Raw: 63 6f 6e 74 65 6e 74 2d 73 65 63 75 72 69 74 79 2d 70 6f 6c 69 63 79 3a 20 73 63 72 69 70 74 2d 73 72 63 20 27 73 65 6c 66 27 20 27 75 6e 73 61 66 65 2d 69 6e 6c 69 6e 65 27 20 27 75 6e 73 61 66 65 2d 65 76 61 6c 27 20 68 74 74 70 73 3a 2f 2f 67 69 73 74 2e 67 69 74 68 75 62 2e 63 6f 6d 20 68 74 74 70 73 3a 2f 2f 61 70 69 73 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 20 68 74 74 70 73 3a 2f 2f 63 64 6e 2e 61 6d 70 6c 69 74 75 64 65 2e 63 6f 6d 20 68 74 74 70 73 3a 2f 2f 61 70 69 2e 61 6d 70 6c 69 74 75 64 65 2e 63 6f 6d 20 68 74 74 70 73 3a 2f 2f 64 65 76 2d 65 6d 62 65 64 2e 6e 6f 74 69 6f 6e 2e 63 6f 20 68 74 74 70 73 3a 2f 2f 65 6d 62 65 64 2e 6e 6f 74 69 6f 6e 2e 63 6f 20 68 74 74 70 73 3a 2f 2f 73 74 61 74 69 63 2e 7a 64 61 73 73 65 74 73 2e 63 6f 6d 20 68 74
        Data Ascii: content-security-policy: script-src 'self' 'unsafe-inline' 'unsafe-eval' https://gist.github.com https://apis.google.com https://cdn.amplitude.com https://api.amplitude.com https://dev-embed.notion.co https://embed.notion.co https://static.zdassets.com ht
        2025-04-22 11:08:33 UTC480INData Raw: 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 6e 6f 74 69 6f 6e 5f 63 68 65 63 6b 5f 63 6f 6f 6b 69 65 5f 63 6f 6e 73 65 6e 74 3d 66 61 6c 73 65 3b 20 44 6f 6d 61 69 6e 3d 65 61 73 74 2d 72 69 66 6c 65 2d 63 63 32 2e 6e 6f 74 69 6f 6e 2e 73 69 74 65 3b 20 50 61 74 68 3d 2f 3b 20 45 78 70 69 72 65 73 3d 57 65 64 2c 20 32 33 20 41 70 72 20 32 30 32 35 20 31 31 3a 30 38 3a 33 33 20 47 4d 54 3b 20 53 65 63 75 72 65 0d 0a 53 65 74 2d 43 6f 6f 6b 69 65 3a 20 5f 5f 63 66 5f 62 6d 3d 55 2e 4b 36 67 51 55 72 58 2e 6f 75 7a 57 37 30 37 41 48 32 70 58 66 4a 4e 52 47 35 77 4f 43 6a 45 6b 70 30 61 32 7a 6b 48 67 73 2d 31 37 34 35 33 32 30 31 31 33 2d 31 2e 30 2e 31 2e 31 2d 54 4c 45 4c 51 5a 6e 5a 7a 47 76 7a 35 36 79 74 6d 55 35 42 76 6f 39 6f 4d 49 53 64 58 53 34 34 74 47 33
        Data Ascii: Set-Cookie: notion_check_cookie_consent=false; Domain=east-rifle-cc2.notion.site; Path=/; Expires=Wed, 23 Apr 2025 11:08:33 GMT; SecureSet-Cookie: __cf_bm=U.K6gQUrX.ouzW707AH2pXfJNRG5wOCjEkp0a2zkHgs-1745320113-1.0.1.1-TLELQZnZzGvz56ytmU5Bvo9oMISdXS44tG3
        2025-04-22 11:08:33 UTC1369INData Raw: 31 30 36 33 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 09 3c 68 65 61 64 3e 0a 09 09 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 20 2f 3e 0a 09 09 3c 74 69 74 6c 65 3e 4e 6f 74 69 6f 6e 3c 2f 74 69 74 6c 65 3e 0a 09 09 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0a 09 09 09 2a 20 7b 0a 09 09 09 09 62 6f 78 2d 73 69 7a 69 6e 67 3a 20 62 6f 72 64 65 72 2d 62 6f 78 3b 0a 09 09 09 7d 0a 09 09 09 68 74 6d 6c 20 7b 0a 09 09 09 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 09 09 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 09 09 7d 0a 09 09 09 62 6f 64 79 20 7b 0a 09 09 09 09 64 69 73 70 6c 61 79 3a 20 66 6c 65 78 3b 0a 09 09 09 09 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 20 63 65 6e 74 65
        Data Ascii: 1063<!DOCTYPE html><html><head><meta charset="utf-8" /><title>Notion</title><style type="text/css">* {box-sizing: border-box;}html {margin: 0;padding: 0;}body {display: flex;justify-content: cente
        2025-04-22 11:08:33 UTC1369INData Raw: 20 61 6e 64 20 28 6d 61 78 2d 77 69 64 74 68 3a 20 39 36 30 70 78 29 20 7b 0a 09 09 09 09 62 6f 64 79 20 7b 0a 09 09 09 09 09 70 61 64 64 69 6e 67 3a 20 32 30 70 78 3b 0a 09 09 09 09 7d 0a 09 09 09 09 2e 64 65 74 61 69 6c 73 20 68 31 20 7b 0a 09 09 09 09 09 64 69 73 70 6c 61 79 3a 20 62 6c 6f 63 6b 3b 0a 09 09 09 09 09 6d 61 72 67 69 6e 2d 62 6f 74 74 6f 6d 3a 20 31 65 6d 3b 0a 09 09 09 09 7d 0a 09 09 09 09 2e 64 65 74 61 69 6c 73 20 6c 69 20 7b 0a 09 09 09 09 09 64 69 73 70 6c 61 79 3a 20 62 6c 6f 63 6b 3b 0a 09 09 09 09 7d 0a 09 09 09 7d 0a 09 09 3c 2f 73 74 79 6c 65 3e 0a 09 3c 2f 68 65 61 64 3e 0a 09 3c 62 6f 64 79 3e 0a 09 09 3c 64 69 76 20 63 6c 61 73 73 3d 22 74 6f 70 22 3e 3c 21 2d 2d 20 46 6f 72 20 61 6c 69 67 6e 6d 65 6e 74 20 70 75 72 70 6f 73
        Data Ascii: and (max-width: 960px) {body {padding: 20px;}.details h1 {display: block;margin-bottom: 1em;}.details li {display: block;}}</style></head><body><div class="top">... For alignment purpos
        2025-04-22 11:08:33 UTC1369INData Raw: 5a 75 54 41 35 4d 42 50 54 30 2f 54 48 49 7a 44 78 63 56 46 57 6a 32 30 51 57 73 43 79 6d 2f 35 39 66 57 56 74 54 34 48 49 58 44 78 70 32 35 75 2b 66 6a 34 79 42 59 50 45 79 47 2b 4b 42 4e 61 45 52 42 43 6f 52 51 79 57 64 4c 43 37 38 7a 6e 63 78 4b 58 49 57 73 64 6a 31 43 74 41 39 4b 76 38 58 69 63 50 74 70 6b 45 71 31 4d 49 76 41 4b 6d 2f 56 41 65 47 35 65 47 5a 58 48 5a 44 49 68 63 58 6d 44 78 50 57 4e 64 4d 45 58 71 2b 64 35 51 44 67 63 61 35 75 47 74 65 4b 42 32 46 4a 68 43 38 35 72 6e 46 42 57 74 34 77 30 53 53 73 65 4b 43 34 5a 70 71 45 46 41 65 41 56 43 42 30 75 4d 70 52 39 6f 37 55 38 45 4a 36 44 32 52 53 68 63 33 52 30 52 43 5a 77 51 72 6b 74 67 6b 75 6b 69 78 59 32 75 79 49 34 41 58 45 2b 39 53 6d 55 67 79 7a 6c 4d 4c 4f 36 6d 4a 68 63 45 47 77
        Data Ascii: ZuTA5MBPT0/THIzDxcVFWj20QWsCym/59fWVtT4HIXDxp25u+fj4yBYPEyG+KBNaERBCoRQyWdLC78zncxKXIWsdj1CtA9Kv8XicPtpkEq1MIvAKm/VAeG5eGZXHZDIhcXmDxPWNdMEXq+d5QDgca5uGteKB2FJhC85rnFBWt4w0SSseKC4ZpqEFAeAVCB0uMpR9o7U8EJ6D2RShc3R0RCZwQrktgkukixY2uyI4AXE+9SmUgyzlMLO6mJhcEGw
        2025-04-22 11:08:33 UTC96INData Raw: 2f 64 69 76 3e 0a 09 09 09 3c 64 69 76 20 73 74 79 6c 65 3d 22 64 69 73 70 6c 61 79 3a 20 6e 6f 6e 65 22 20 63 6c 61 73 73 3d 22 64 65 74 61 69 6c 73 2d 65 78 70 61 6e 64 65 64 22 3e 3c 2f 64 69 76 3e 0a 09 09 3c 2f 64 69 76 3e 0a 09 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a 0d 0a
        Data Ascii: /div><div style="display: none" class="details-expanded"></div></div></body></html>
        2025-04-22 11:08:33 UTC5INData Raw: 30 0d 0a 0d 0a
        Data Ascii: 0


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.2460836208.103.161.324433472C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-04-22 11:08:33 UTC829OUTGET /favicon.ico HTTP/1.1
        Host: east-rifle-cc2.notion.site
        Connection: keep-alive
        sec-ch-ua-platform: "Windows"
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
        sec-ch-ua-mobile: ?0
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://east-rifle-cc2.notion.site/Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=4
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9
        Cookie: notion_browser_id=585ef809-4eda-4365-9fac-07de7b4d7ba0; device_id=1ddd872b-594c-819b-aa35-003bd2a820d8; notion_check_cookie_consent=false
        2025-04-22 11:08:33 UTC347INHTTP/1.1 404 Not Found
        Date: Tue, 22 Apr 2025 11:08:33 GMT
        Content-Type: application/json; charset=utf-8
        Content-Length: 28
        Connection: close
        CF-Ray: 9344a9f66e6b720e-PHX
        CF-Cache-Status: HIT
        Age: 192
        ETag: W/"1c-rse+oIWWZjJFS4zo55aR8QTCsdg"
        Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
        Vary: Accept-Encoding
        2025-04-22 11:08:33 UTC6198INData Raw: 63 6f 6e 74 65 6e 74 2d 73 65 63 75 72 69 74 79 2d 70 6f 6c 69 63 79 3a 20 73 63 72 69 70 74 2d 73 72 63 20 27 73 65 6c 66 27 20 27 75 6e 73 61 66 65 2d 69 6e 6c 69 6e 65 27 20 27 75 6e 73 61 66 65 2d 65 76 61 6c 27 20 68 74 74 70 73 3a 2f 2f 67 69 73 74 2e 67 69 74 68 75 62 2e 63 6f 6d 20 68 74 74 70 73 3a 2f 2f 61 70 69 73 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 20 68 74 74 70 73 3a 2f 2f 63 64 6e 2e 61 6d 70 6c 69 74 75 64 65 2e 63 6f 6d 20 68 74 74 70 73 3a 2f 2f 61 70 69 2e 61 6d 70 6c 69 74 75 64 65 2e 63 6f 6d 20 68 74 74 70 73 3a 2f 2f 64 65 76 2d 65 6d 62 65 64 2e 6e 6f 74 69 6f 6e 2e 63 6f 20 68 74 74 70 73 3a 2f 2f 65 6d 62 65 64 2e 6e 6f 74 69 6f 6e 2e 63 6f 20 68 74 74 70 73 3a 2f 2f 73 74 61 74 69 63 2e 7a 64 61 73 73 65 74 73 2e 63 6f 6d 20 68 74
        Data Ascii: content-security-policy: script-src 'self' 'unsafe-inline' 'unsafe-eval' https://gist.github.com https://apis.google.com https://cdn.amplitude.com https://api.amplitude.com https://dev-embed.notion.co https://embed.notion.co https://static.zdassets.com ht
        2025-04-22 11:08:33 UTC28INData Raw: 7b 22 6d 65 73 73 61 67 65 22 3a 22 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 22 7d
        Data Ascii: {"message":"File not found"}


        020406080s020406080100

        Click to jump to process

        020406080s0.0050100MB

        Click to jump to process

        Target ID:0
        Start time:07:08:24
        Start date:22/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff773ba0000
        File size:3'384'928 bytes
        MD5 hash:DBE43C1D0092437B88CFF7BD9ABC336C
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:07:08:25
        Start date:22/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1996,i,10975350230579627962,12600055534810953432,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250316-180048.776000 --mojo-platform-channel-handle=2104 /prefetch:11
        Imagebase:0x7ff773ba0000
        File size:3'384'928 bytes
        MD5 hash:DBE43C1D0092437B88CFF7BD9ABC336C
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:5
        Start time:07:08:31
        Start date:22/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://east-rifle-cc2.notion.site/Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=4"
        Imagebase:0x7ff773ba0000
        File size:3'384'928 bytes
        MD5 hash:DBE43C1D0092437B88CFF7BD9ABC336C
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly