Glossary
kMDItemWhereFroms
The com.apple.metadata:kMDItemWhereFroms attribute: a binary plist array of strings, usually the download URL and the referring page.
com.apple.metadata:kMDItemWhereFroms is an extended attribute holding a binary property list array of strings, set by browsers and Mail. For a browser download it usually contains the download URL and the referrer or page; for a Mail attachment, the sender and subject-like strings. mdls -name kMDItemWhereFroms file reads it through Spotlight.
It is separate from the quarantine attribute: xattr -d com.apple.quarantine removes the quarantine value and leaves WhereFroms in place. A file that keeps WhereFroms but has no quarantine attribute may have been cleaned that way, which is a lead to check, not proof. Both attributes also survive in AppleDouble files on volumes without extended attributes. See kMDItemWhereFroms vs quarantine.