{
  "type": "URL",
  "indicator": "http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "akamai",
        "message": "Akamai rank: #94",
        "name": "Akamai Popular Domain"
      },
      {
        "source": "whitelist",
        "message": "Whitelisted domain digicert.com",
        "name": "Whitelisted domain"
      },
      {
        "source": "majestic",
        "message": "Whitelisted domain digicert.com",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 3793609762,
      "indicator": "http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "6862f3dfadf9868777a97d96",
          "name": "LokiBot \u2022 Denver Apartments & Townhomes for Rent |",
          "description": "| ENDGAME |\n\u2022 ALF:Trojan:MSIL/LokiBot.BY!MTBv\n\u2022 Win32:MalwareX-gen\\ [Trj\n| w3.org - 324 malicious files communicating |\n{https://otx.alienvault.com/indicator/file/4fe0a2474da348b703e074cd0e951b09b1152bb9c571eddc268e4ee82178ca0f}\n\n\u2022 Trojan:Win32/Gepys.PVS!MTB\tMalware infection\n\u2022 www.endgame.com/blog/technical-blog/ten-process-injection-techniques-technical-survey-common-and-trending-process\n\u2022 www.endgame.com/\n(Researcher: CHRIS KRAYBILL?? | Emails\tG5DEV@G5SEARCHMARKETING.COM |  Chief Technology Officer of Amplion, Inc)\n! SELL.INTERNETTRAFFIC.COM !\nDescribed as Upscale living.\nMonitoring/Hacking/ Targeting/ Crime/ Keyloggers\n\nUnsafe connections & logging.\n[404/Snake/Matiex Keylogger Style External IP Check\nPossible HTTP 403 XSS Attempt (Local Source)\nDYNAMIC_DNS Query to *.duckdns. Domain]\n[https://otx.alienvault.com/indicator/file/4fe0a2474da348b703e074cd0e951b09b1152bb9c571eddc268e4ee82178ca0f]",
          "modified": "2025-07-30T20:03:49.035000",
          "created": "2025-06-30T20:30:23.414000",
          "tags": [
            "passive dns",
            "urls",
            "files ip",
            "address",
            "moved",
            "script urls",
            "creation date",
            "search",
            "record value",
            "date",
            "body",
            "x cache",
            "hio50 c1",
            "x amz",
            "read c",
            "document file",
            "v2 document",
            "tls handshake",
            "failure",
            "write",
            "show",
            "port",
            "destination",
            "copy",
            "malware",
            "next",
            "domains show",
            "domain related",
            "memcommit",
            "cryptexportkey",
            "invalid pointer",
            "medium",
            "icmp traffic",
            "t1055",
            "http",
            "memreserve",
            "windows",
            "checks amount",
            "msie",
            "windows nt",
            "wow64",
            "slcc2",
            "media center",
            "hostname",
            "files domain",
            "files related",
            "pulses none",
            "related tags",
            "none google",
            "safe browsing",
            "no expiration",
            "url https",
            "expiration",
            "domain",
            "sec ch",
            "ch ua",
            "ua full",
            "ua platform",
            "united",
            "cname",
            "present jun",
            "entries",
            "ip address",
            "name servers",
            "showing",
            "domain add",
            "present may",
            "next associated",
            "urls show",
            "date checked",
            "url hostname",
            "response ip",
            "address google",
            "present sep",
            "present dec",
            "present nov",
            "unique",
            "url add",
            "pulse pulses",
            "related nids",
            "files location",
            "code",
            "present apr",
            "status",
            "private name",
            "org domains",
            "proxy",
            "llc address",
            "road city",
            "us creation",
            "domain name",
            "aaaa",
            "trojan",
            "yara detections",
            "alerts",
            "analysis date",
            "file score",
            "mtb yara",
            "detections none",
            "related pulses",
            "none related",
            "win32",
            "expiration date",
            "title error",
            "hostname add",
            "pulse submit",
            "entries http",
            "scans record",
            "value",
            "a domains",
            "server",
            "gmt content",
            "length",
            "flywheel",
            "sea x",
            "miss x",
            "accept",
            "meta",
            "pulses",
            "tags",
            "otx telemetry",
            "twitter running",
            "open ports",
            "certificate",
            "cookie",
            "flag united",
            "local",
            "unknown ns",
            "unknown soa",
            "external ip",
            "process32nextw",
            "lookup",
            "dyndns checkip",
            "address server",
            "response",
            "savbwcd",
            "ef3ghigj",
            "abxcde",
            "unknown",
            "info",
            "amazon",
            "amazon rsa",
            "location united",
            "asn as16509",
            "whois registrar",
            "none indicator",
            "facts otx",
            "referral url",
            "solutions",
            "whois server",
            "query",
            "contacted",
            "pulse",
            "av detections",
            "ids detections",
            "detections"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1081",
              "name": "Credentials in Files",
              "display_name": "T1081 - Credentials in Files"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 576,
            "FileHash-SHA1": 534,
            "hostname": 212,
            "URL": 149,
            "domain": 683,
            "email": 10,
            "FileHash-SHA256": 1925,
            "SSLCertFingerprint": 1
          },
          "indicator_count": 4090,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 146,
          "modified_text": "308 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "656e374fca501572766cea17",
          "name": "Discord Ransomware |  ConventionEngine",
          "description": "Contacted\n162.159.128.233\nDomain Contacted\ndiscord.com",
          "modified": "2024-01-03T19:02:48.293000",
          "created": "2023-12-04T20:32:15.139000",
          "tags": [
            "entries",
            "search",
            "ms windows",
            "show",
            "showing",
            "intel",
            "windows",
            "delete c",
            "crlf line",
            "yara detections",
            "ransom",
            "copy",
            "write",
            "june",
            "guard",
            "malware",
            "push",
            "next",
            "error",
            "unicode text",
            "utf16",
            "delphi",
            "win32"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 575,
            "FileHash-SHA1": 563,
            "FileHash-SHA256": 1542,
            "URL": 68,
            "hostname": 40,
            "domain": 19,
            "email": 2
          },
          "indicator_count": 2809,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "882 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "656f37ed39f553c0587732ec",
          "name": "Discord Ransomware | Intel | ConventionEngine",
          "description": "",
          "modified": "2024-01-03T19:02:48.293000",
          "created": "2023-12-05T14:47:09.799000",
          "tags": [
            "entries",
            "search",
            "ms windows",
            "show",
            "showing",
            "intel",
            "windows",
            "delete c",
            "crlf line",
            "yara detections",
            "ransom",
            "copy",
            "write",
            "june",
            "guard",
            "malware",
            "push",
            "next",
            "error",
            "unicode text",
            "utf16",
            "delphi",
            "win32"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "656e374fca501572766cea17",
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 575,
            "FileHash-SHA1": 563,
            "FileHash-SHA256": 1542,
            "URL": 68,
            "hostname": 40,
            "domain": 19,
            "email": 2
          },
          "indicator_count": 2809,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "882 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 8160
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/digicert.com",
    "whois": "http://whois.domaintools.com/digicert.com",
    "domain": "digicert.com",
    "hostname": "crl4.digicert.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "6862f3dfadf9868777a97d96",
      "name": "LokiBot \u2022 Denver Apartments & Townhomes for Rent |",
      "description": "| ENDGAME |\n\u2022 ALF:Trojan:MSIL/LokiBot.BY!MTBv\n\u2022 Win32:MalwareX-gen\\ [Trj\n| w3.org - 324 malicious files communicating |\n{https://otx.alienvault.com/indicator/file/4fe0a2474da348b703e074cd0e951b09b1152bb9c571eddc268e4ee82178ca0f}\n\n\u2022 Trojan:Win32/Gepys.PVS!MTB\tMalware infection\n\u2022 www.endgame.com/blog/technical-blog/ten-process-injection-techniques-technical-survey-common-and-trending-process\n\u2022 www.endgame.com/\n(Researcher: CHRIS KRAYBILL?? | Emails\tG5DEV@G5SEARCHMARKETING.COM |  Chief Technology Officer of Amplion, Inc)\n! SELL.INTERNETTRAFFIC.COM !\nDescribed as Upscale living.\nMonitoring/Hacking/ Targeting/ Crime/ Keyloggers\n\nUnsafe connections & logging.\n[404/Snake/Matiex Keylogger Style External IP Check\nPossible HTTP 403 XSS Attempt (Local Source)\nDYNAMIC_DNS Query to *.duckdns. Domain]\n[https://otx.alienvault.com/indicator/file/4fe0a2474da348b703e074cd0e951b09b1152bb9c571eddc268e4ee82178ca0f]",
      "modified": "2025-07-30T20:03:49.035000",
      "created": "2025-06-30T20:30:23.414000",
      "tags": [
        "passive dns",
        "urls",
        "files ip",
        "address",
        "moved",
        "script urls",
        "creation date",
        "search",
        "record value",
        "date",
        "body",
        "x cache",
        "hio50 c1",
        "x amz",
        "read c",
        "document file",
        "v2 document",
        "tls handshake",
        "failure",
        "write",
        "show",
        "port",
        "destination",
        "copy",
        "malware",
        "next",
        "domains show",
        "domain related",
        "memcommit",
        "cryptexportkey",
        "invalid pointer",
        "medium",
        "icmp traffic",
        "t1055",
        "http",
        "memreserve",
        "windows",
        "checks amount",
        "msie",
        "windows nt",
        "wow64",
        "slcc2",
        "media center",
        "hostname",
        "files domain",
        "files related",
        "pulses none",
        "related tags",
        "none google",
        "safe browsing",
        "no expiration",
        "url https",
        "expiration",
        "domain",
        "sec ch",
        "ch ua",
        "ua full",
        "ua platform",
        "united",
        "cname",
        "present jun",
        "entries",
        "ip address",
        "name servers",
        "showing",
        "domain add",
        "present may",
        "next associated",
        "urls show",
        "date checked",
        "url hostname",
        "response ip",
        "address google",
        "present sep",
        "present dec",
        "present nov",
        "unique",
        "url add",
        "pulse pulses",
        "related nids",
        "files location",
        "code",
        "present apr",
        "status",
        "private name",
        "org domains",
        "proxy",
        "llc address",
        "road city",
        "us creation",
        "domain name",
        "aaaa",
        "trojan",
        "yara detections",
        "alerts",
        "analysis date",
        "file score",
        "mtb yara",
        "detections none",
        "related pulses",
        "none related",
        "win32",
        "expiration date",
        "title error",
        "hostname add",
        "pulse submit",
        "entries http",
        "scans record",
        "value",
        "a domains",
        "server",
        "gmt content",
        "length",
        "flywheel",
        "sea x",
        "miss x",
        "accept",
        "meta",
        "pulses",
        "tags",
        "otx telemetry",
        "twitter running",
        "open ports",
        "certificate",
        "cookie",
        "flag united",
        "local",
        "unknown ns",
        "unknown soa",
        "external ip",
        "process32nextw",
        "lookup",
        "dyndns checkip",
        "address server",
        "response",
        "savbwcd",
        "ef3ghigj",
        "abxcde",
        "unknown",
        "info",
        "amazon",
        "amazon rsa",
        "location united",
        "asn as16509",
        "whois registrar",
        "none indicator",
        "facts otx",
        "referral url",
        "solutions",
        "whois server",
        "query",
        "contacted",
        "pulse",
        "av detections",
        "ids detections",
        "detections"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1081",
          "name": "Credentials in Files",
          "display_name": "T1081 - Credentials in Files"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 576,
        "FileHash-SHA1": 534,
        "hostname": 212,
        "URL": 149,
        "domain": 683,
        "email": 10,
        "FileHash-SHA256": 1925,
        "SSLCertFingerprint": 1
      },
      "indicator_count": 4090,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 146,
      "modified_text": "308 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "656e374fca501572766cea17",
      "name": "Discord Ransomware |  ConventionEngine",
      "description": "Contacted\n162.159.128.233\nDomain Contacted\ndiscord.com",
      "modified": "2024-01-03T19:02:48.293000",
      "created": "2023-12-04T20:32:15.139000",
      "tags": [
        "entries",
        "search",
        "ms windows",
        "show",
        "showing",
        "intel",
        "windows",
        "delete c",
        "crlf line",
        "yara detections",
        "ransom",
        "copy",
        "write",
        "june",
        "guard",
        "malware",
        "push",
        "next",
        "error",
        "unicode text",
        "utf16",
        "delphi",
        "win32"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 575,
        "FileHash-SHA1": 563,
        "FileHash-SHA256": 1542,
        "URL": 68,
        "hostname": 40,
        "domain": 19,
        "email": 2
      },
      "indicator_count": 2809,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "882 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "656f37ed39f553c0587732ec",
      "name": "Discord Ransomware | Intel | ConventionEngine",
      "description": "",
      "modified": "2024-01-03T19:02:48.293000",
      "created": "2023-12-05T14:47:09.799000",
      "tags": [
        "entries",
        "search",
        "ms windows",
        "show",
        "showing",
        "intel",
        "windows",
        "delete c",
        "crlf line",
        "yara detections",
        "ransom",
        "copy",
        "write",
        "june",
        "guard",
        "malware",
        "push",
        "next",
        "error",
        "unicode text",
        "utf16",
        "delphi",
        "win32"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "656e374fca501572766cea17",
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 575,
        "FileHash-SHA1": 563,
        "FileHash-SHA256": 1542,
        "URL": 68,
        "hostname": 40,
        "domain": 19,
        "email": 2
      },
      "indicator_count": 2809,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "882 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "type": "URL",
    "indicator": "http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L",
    "stats": {
      "malicious": 0,
      "suspicious": 0,
      "harmless": 72,
      "undetected": 18,
      "total": 90,
      "verdict": "clean",
      "ratio": "0/90"
    },
    "verdict": "clean",
    "ratio": "0/90",
    "final_url": "http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L",
    "title": "404 Not Found",
    "reputation": 0,
    "tags": [],
    "top_detections": [],
    "last_analysis": 1701780569,
    "error": null
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780531313.5274327
}