{
  "type": "URL",
  "indicator": "https://goVoteColorado.gov",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://goVoteColorado.gov",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4127422067,
      "indicator": "https://goVoteColorado.gov",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "6952f958f5dee394ed5ee9f1",
          "name": "Agent-AQB -Secretary of State Colorado",
          "description": "There are several compromised certificate on Secretary of State Colorado. I focused on one.\nMalicious - Writes to STDOUT",
          "modified": "2026-01-28T21:05:58.898000",
          "created": "2025-12-29T21:57:44.075000",
          "tags": [
            "subscribe",
            "unsubscribe",
            "s paris",
            "englewood",
            "united",
            "state",
            "skip",
            "espaol",
            "summary",
            "filing history",
            "present jul",
            "a domains",
            "present jun",
            "present oct",
            "present dec",
            "script urls",
            "present aug",
            "moved",
            "link",
            "meta",
            "msie",
            "chrome",
            "passive dns",
            "gmt content",
            "ipv4",
            "urls",
            "files",
            "title",
            "ipv4 add",
            "america flag",
            "america asn",
            "related pulses",
            "united states",
            "cloudflare a",
            "div div",
            "span span",
            "domain",
            "cloudflare",
            "content type",
            "click",
            "dynamicloader",
            "get opera",
            "host",
            "tlsv1",
            "install",
            "external ip",
            "lookup",
            "intel",
            "ms windows",
            "ogoogle trust",
            "write",
            "malware",
            "ip address",
            "search",
            "present nov",
            "backdoor",
            "bq dec",
            "win32small dec",
            "next associated",
            "virtool",
            "reverse dns",
            "australia asn",
            "twitter",
            "status",
            "name servers",
            "expiration date",
            "hostname add",
            "unknown soa",
            "domain add",
            "form",
            "entries",
            "url analysis",
            "error",
            "body",
            "date",
            "high",
            "ssh scan",
            "tcp syn",
            "resolverror",
            "show",
            "outbound",
            "yara detections",
            "potential ssh",
            "contacted",
            "copy",
            "icmp traffic",
            "dns query",
            "therahand certificat",
            "sos",
            "secretary of state",
            "writes_to_stdout"
          ],
          "references": [
            "https://www.coloradosos.gov/biz/BusinessEntityDetail.do?quitButtonDestination=BusinessEntityResults&nameTyp=ENT&masterFileId=20221473927&entityId2=20221473927&fileId=20251525819&srchTyp=ENTITY",
            "ELF:Agent-AQB\\ [Trj] IDS Detections: Potential SSH Scan Potential SSH Scan OUTBOUND",
            "Yara Detections: is__elf",
            "Alerts: dead_host known_hosts_conn network_icmp tcp_syn_scan osquery_detection",
            "Alerts: nolookup_communication writes_to_stdout",
            "IP\u2019s Contacted 2530 IP\u2019s Contacted  1.0.0.1  1.0.0.10  1.0.0.100  1.0.0.101  1.0.0.102 | Domains Contacted: 9654s.com",
            "https://otx.alienvault.com/indicator/file/aeb3d5ec1d144a7b2d51bdb603c052fd52700defb1b039491c4df3f32ece517a",
            "ELF:Agent-AQB\\ [Trj]",
            "https://otx.alienvault.com/indicator/file/aeb3d5ec1d144a7b2d51bdb603c052fd52700defb1b039491c4df3f32ece517a"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Win.Trojan.Agent-31853",
              "display_name": "Win.Trojan.Agent-31853",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Small.IR",
              "display_name": "Backdoor:Win32/Small.IR",
              "target": "/malware/Backdoor:Win32/Small.IR"
            },
            {
              "id": "Win.Downloader.92-4",
              "display_name": "Win.Downloader.92-4",
              "target": null
            },
            {
              "id": "Win.Trojan.Fugrafa-9733007-0",
              "display_name": "Win.Trojan.Fugrafa-9733007-0",
              "target": null
            },
            {
              "id": "ELF:Agent-AQB\\ [Trj]",
              "display_name": "ELF:Agent-AQB\\ [Trj]",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1561,
            "domain": 158,
            "hostname": 637,
            "FileHash-MD5": 121,
            "FileHash-SHA1": 97,
            "email": 8,
            "FileHash-SHA256": 561,
            "SSLCertFingerprint": 1
          },
          "indicator_count": 3144,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 142,
          "modified_text": "122 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "68bbf3e40e3ce8a74aa89545",
          "name": "HCPF \u2022 The intricate relationships between the FIN7 group and members of the Conti gang",
          "description": "",
          "modified": "2025-10-06T08:03:23.285000",
          "created": "2025-09-06T08:42:12.787000",
          "tags": [
            "present feb",
            "united",
            "a domains",
            "present dec",
            "passive dns",
            "moved",
            "script domains",
            "script urls",
            "search",
            "title",
            "date",
            "http traffic",
            "http get",
            "match info",
            "downloads",
            "info",
            "https http",
            "mitre att",
            "control ta0011",
            "protocol t1071",
            "protocol t1095",
            "get http",
            "dns resolutions",
            "number",
            "azure rsa",
            "tls issuing",
            "cus subject",
            "stwa lredmond",
            "corporation cus",
            "algorithm",
            "cnamazon rsa",
            "m03 oamazon",
            "thumbprint",
            "msie",
            "windows nt",
            "wow64",
            "slcc2",
            "media center",
            "tlsv1",
            "ascii text",
            "ogoogle trust",
            "cngts ca",
            "execution",
            "next",
            "dock",
            "write",
            "capture",
            "persistence",
            "malware",
            "roboto",
            "android",
            "known exploited",
            "google",
            "salesloft drift",
            "sap s4hana",
            "cve202542957",
            "cisa",
            "sitecore",
            "linux",
            "france",
            "meta",
            "rokrat",
            "lizar",
            "project nemesis",
            "carbanak",
            "cobalt strike",
            "domino",
            "yara detections",
            "contacted",
            "av detections",
            "ids detections",
            "alerts",
            "analysis date",
            "file score",
            "malicious ids",
            "detections tls",
            "indicator role",
            "title added",
            "active related",
            "entries",
            "role title",
            "added active",
            "filehashmd5",
            "ipv4"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Lizar",
              "display_name": "Lizar",
              "target": null
            },
            {
              "id": "Project Nemesis",
              "display_name": "Project Nemesis",
              "target": null
            },
            {
              "id": "Carbanak",
              "display_name": "Carbanak",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Domino",
              "display_name": "Domino",
              "target": null
            },
            {
              "id": "RokRAT",
              "display_name": "RokRAT",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            }
          ],
          "industries": [
            "Hospitality",
            "Financial"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 22,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 539,
            "FileHash-SHA1": 389,
            "FileHash-SHA256": 3386,
            "domain": 862,
            "hostname": 1155,
            "URL": 4091,
            "CVE": 3,
            "SSLCertFingerprint": 5
          },
          "indicator_count": 10430,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 144,
          "modified_text": "237 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "Alerts: dead_host known_hosts_conn network_icmp tcp_syn_scan osquery_detection",
        "ELF:Agent-AQB\\ [Trj] IDS Detections: Potential SSH Scan Potential SSH Scan OUTBOUND",
        "https://www.coloradosos.gov/biz/BusinessEntityDetail.do?quitButtonDestination=BusinessEntityResults&nameTyp=ENT&masterFileId=20221473927&entityId2=20221473927&fileId=20251525819&srchTyp=ENTITY",
        "Alerts: nolookup_communication writes_to_stdout",
        "https://otx.alienvault.com/indicator/file/aeb3d5ec1d144a7b2d51bdb603c052fd52700defb1b039491c4df3f32ece517a",
        "ELF:Agent-AQB\\ [Trj]",
        "Yara Detections: is__elf",
        "IP\u2019s Contacted 2530 IP\u2019s Contacted  1.0.0.1  1.0.0.10  1.0.0.100  1.0.0.101  1.0.0.102 | Domains Contacted: 9654s.com"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Project nemesis",
            "Backdoor:win32/small.ir",
            "Lizar",
            "Carbanak",
            "Elf:agent-aqb\\ [trj]",
            "Rokrat",
            "Win.trojan.fugrafa-9733007-0",
            "Win.trojan.agent-31853",
            "Domino",
            "Win.downloader.92-4",
            "Cobalt strike"
          ],
          "industries": [
            "Financial",
            "Hospitality"
          ],
          "unique_indicators": 13856
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/goVoteColorado.gov",
    "whois": "http://whois.domaintools.com/goVoteColorado.gov",
    "domain": "goVoteColorado.gov",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "6952f958f5dee394ed5ee9f1",
      "name": "Agent-AQB -Secretary of State Colorado",
      "description": "There are several compromised certificate on Secretary of State Colorado. I focused on one.\nMalicious - Writes to STDOUT",
      "modified": "2026-01-28T21:05:58.898000",
      "created": "2025-12-29T21:57:44.075000",
      "tags": [
        "subscribe",
        "unsubscribe",
        "s paris",
        "englewood",
        "united",
        "state",
        "skip",
        "espaol",
        "summary",
        "filing history",
        "present jul",
        "a domains",
        "present jun",
        "present oct",
        "present dec",
        "script urls",
        "present aug",
        "moved",
        "link",
        "meta",
        "msie",
        "chrome",
        "passive dns",
        "gmt content",
        "ipv4",
        "urls",
        "files",
        "title",
        "ipv4 add",
        "america flag",
        "america asn",
        "related pulses",
        "united states",
        "cloudflare a",
        "div div",
        "span span",
        "domain",
        "cloudflare",
        "content type",
        "click",
        "dynamicloader",
        "get opera",
        "host",
        "tlsv1",
        "install",
        "external ip",
        "lookup",
        "intel",
        "ms windows",
        "ogoogle trust",
        "write",
        "malware",
        "ip address",
        "search",
        "present nov",
        "backdoor",
        "bq dec",
        "win32small dec",
        "next associated",
        "virtool",
        "reverse dns",
        "australia asn",
        "twitter",
        "status",
        "name servers",
        "expiration date",
        "hostname add",
        "unknown soa",
        "domain add",
        "form",
        "entries",
        "url analysis",
        "error",
        "body",
        "date",
        "high",
        "ssh scan",
        "tcp syn",
        "resolverror",
        "show",
        "outbound",
        "yara detections",
        "potential ssh",
        "contacted",
        "copy",
        "icmp traffic",
        "dns query",
        "therahand certificat",
        "sos",
        "secretary of state",
        "writes_to_stdout"
      ],
      "references": [
        "https://www.coloradosos.gov/biz/BusinessEntityDetail.do?quitButtonDestination=BusinessEntityResults&nameTyp=ENT&masterFileId=20221473927&entityId2=20221473927&fileId=20251525819&srchTyp=ENTITY",
        "ELF:Agent-AQB\\ [Trj] IDS Detections: Potential SSH Scan Potential SSH Scan OUTBOUND",
        "Yara Detections: is__elf",
        "Alerts: dead_host known_hosts_conn network_icmp tcp_syn_scan osquery_detection",
        "Alerts: nolookup_communication writes_to_stdout",
        "IP\u2019s Contacted 2530 IP\u2019s Contacted  1.0.0.1  1.0.0.10  1.0.0.100  1.0.0.101  1.0.0.102 | Domains Contacted: 9654s.com",
        "https://otx.alienvault.com/indicator/file/aeb3d5ec1d144a7b2d51bdb603c052fd52700defb1b039491c4df3f32ece517a",
        "ELF:Agent-AQB\\ [Trj]",
        "https://otx.alienvault.com/indicator/file/aeb3d5ec1d144a7b2d51bdb603c052fd52700defb1b039491c4df3f32ece517a"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Win.Trojan.Agent-31853",
          "display_name": "Win.Trojan.Agent-31853",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Small.IR",
          "display_name": "Backdoor:Win32/Small.IR",
          "target": "/malware/Backdoor:Win32/Small.IR"
        },
        {
          "id": "Win.Downloader.92-4",
          "display_name": "Win.Downloader.92-4",
          "target": null
        },
        {
          "id": "Win.Trojan.Fugrafa-9733007-0",
          "display_name": "Win.Trojan.Fugrafa-9733007-0",
          "target": null
        },
        {
          "id": "ELF:Agent-AQB\\ [Trj]",
          "display_name": "ELF:Agent-AQB\\ [Trj]",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1561,
        "domain": 158,
        "hostname": 637,
        "FileHash-MD5": 121,
        "FileHash-SHA1": 97,
        "email": 8,
        "FileHash-SHA256": 561,
        "SSLCertFingerprint": 1
      },
      "indicator_count": 3144,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 142,
      "modified_text": "122 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "68bbf3e40e3ce8a74aa89545",
      "name": "HCPF \u2022 The intricate relationships between the FIN7 group and members of the Conti gang",
      "description": "",
      "modified": "2025-10-06T08:03:23.285000",
      "created": "2025-09-06T08:42:12.787000",
      "tags": [
        "present feb",
        "united",
        "a domains",
        "present dec",
        "passive dns",
        "moved",
        "script domains",
        "script urls",
        "search",
        "title",
        "date",
        "http traffic",
        "http get",
        "match info",
        "downloads",
        "info",
        "https http",
        "mitre att",
        "control ta0011",
        "protocol t1071",
        "protocol t1095",
        "get http",
        "dns resolutions",
        "number",
        "azure rsa",
        "tls issuing",
        "cus subject",
        "stwa lredmond",
        "corporation cus",
        "algorithm",
        "cnamazon rsa",
        "m03 oamazon",
        "thumbprint",
        "msie",
        "windows nt",
        "wow64",
        "slcc2",
        "media center",
        "tlsv1",
        "ascii text",
        "ogoogle trust",
        "cngts ca",
        "execution",
        "next",
        "dock",
        "write",
        "capture",
        "persistence",
        "malware",
        "roboto",
        "android",
        "known exploited",
        "google",
        "salesloft drift",
        "sap s4hana",
        "cve202542957",
        "cisa",
        "sitecore",
        "linux",
        "france",
        "meta",
        "rokrat",
        "lizar",
        "project nemesis",
        "carbanak",
        "cobalt strike",
        "domino",
        "yara detections",
        "contacted",
        "av detections",
        "ids detections",
        "alerts",
        "analysis date",
        "file score",
        "malicious ids",
        "detections tls",
        "indicator role",
        "title added",
        "active related",
        "entries",
        "role title",
        "added active",
        "filehashmd5",
        "ipv4"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Lizar",
          "display_name": "Lizar",
          "target": null
        },
        {
          "id": "Project Nemesis",
          "display_name": "Project Nemesis",
          "target": null
        },
        {
          "id": "Carbanak",
          "display_name": "Carbanak",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Domino",
          "display_name": "Domino",
          "target": null
        },
        {
          "id": "RokRAT",
          "display_name": "RokRAT",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1571",
          "name": "Non-Standard Port",
          "display_name": "T1571 - Non-Standard Port"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        }
      ],
      "industries": [
        "Hospitality",
        "Financial"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 22,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 539,
        "FileHash-SHA1": 389,
        "FileHash-SHA256": 3386,
        "domain": 862,
        "hostname": 1155,
        "URL": 4091,
        "CVE": 3,
        "SSLCertFingerprint": 5
      },
      "indicator_count": 10430,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 144,
      "modified_text": "237 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://goVoteColorado.gov",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://goVoteColorado.gov",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780225546.125403
}