Security Scan Report: www.spark.co.nz

Redirected to:
https://signin.spark.co.nz/?goto=https://www.spark.co.nz/xtramail/chec...
Site favicon
Submitted: May 15, 2026, 1:18:48 AMCompleted: May 15, 2026, 1:20:33 AMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 2 countries across 3 domains to perform 20 HTTP transactions. The main domain is signin.spark.co.nz.

Submitted URL: https://www.spark.co.nz/cwa/openam/SSORedirect/metaAlias/Xtramail/idp1?SAMLRequest=hZJbbxMxEIX%2Fysrvu95tbsVKIrlJK0UqUCWAEC%2BV60xVq77hme0Wfj32BlB4KU%2B2ZuZoznfsJSpno5A9Pfk9fO8BqXp11qMYGyvWJy%2BCQoPCKwcoSIuDfH8rLppWxBQo6GDZmeRthUKERCZ4Vu22K3Z%2FOZ8uJtfdYvFuItvNTMrJQl5dzW9mc9nl25RVXyBhnl%2BxLM8ixB52Hkl5yqX2Yl63s7qbfWo70V2K6eQbq7aZwXhFo%2BqJKKLgfBiGBqNKz40Ojf%2FJ9aB4iJAd8sPh4x6OJoEm7oCUtEYh%2F0pJOWUsN8fYsWoTPELZ%2BRadPg0J3aeUz9q4aI02xKqbkDSMIa%2FYo7IIBeUup2Fe4G9F%2FgmnLOsdpAOkF6Ph8%2F72DAQeiq3mNfv7zeLA2uB5DEh7wFhMsPWyPIYY80prFSP2hqAuxZqGtOTn7eXpE3zIQLvtXciefxTHTv2Ht1TMsX4cR0U25NFk7kySDQ2bBIoyHaUeGF%2BfVv771da%2FAA%3D%3D&RelayState=https%3A%2F%2Fwebmail.xtra.co.nz%2Findex.cgi&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=LvrAmYCV5hBC0DVOTTpy6cNljal4%2F%2Bder6mZ3Omr%2FRyhpzzmijxyj%2FYRjPz8Aa%2BTTqdHWxB89RHk4nPautUdLz5otiFTu%2Fit4tdu8ET0tdzrplgFTi6oOqvzRZEE7G%2B1WnBMM7ayzO9USqB4UYHOW%2F5AuXqqKB5iYi%2B3E%2BzBMD3Ws3fP3rB%2F86YTLq2zoOrMXygezwPTaek5R2hD0lWmR%2BrlnQtcEMJdPzn1iNmc%2Fz%2Fys8fPtApJ5%2BQXBJMMBHtREa1TI0Iloa05aI2OY66JGqpPonwybqyUzy0pD9WYxf%2Bqq8eLyWp2v5q%2BCbZXdevC%2F2S5GA86YzoPBlwDvDQsiw%3D%3D

Effective URL: https://signin.spark.co.nz/?goto=https://www.spark.co.nz/xtramail/checkcookies?spEntityID%3Dappsuite-saml-twr%26goto%3Dhttp://openam.internal.spark.co.nz:8080/openam/saml2/continue/metaAlias/Xtramail/idp1?secondVisitUrl%253D/SSORedirect/metaAlias/Xtramail/idp1?ReqID%25253D_86473E17793A0C5AA37ABB6F56A17AB4%26AMAuthCookie%3D&brand=xtramailRedirected

The Cisco Umbrella rank of the primary domain is #416,869 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 92%

9
Risk Score

The site presents a credential‑phishing login for Xtra Mail, has unknown domain age, low ranking, and multiple critical IDS alerts, indicating high risk.

Risk Factors
Low domain ranking for a brand claim
Unknown domain age with credential form
Critical IDS alerts (malware/C2)
High JavaScript obfuscation and use of Function() constructor
Potential brand impersonation
Domain age information unavailable

Details

Page Title

Sign in

Scan Type

public

Language

🇺🇸

English

(54% confidence)

Category

healthcare medical

(29%)

Domain Information

Domain 'www.spark.co.nz' uses the New Zealand country-code top-level domain (.co.nz) and includes subdomain 'www'. Its registrable label 'spark' stretches across 5 characters containing 1 vowel alongside four consonants. Word splitting yields 1 word: spark. Median word length comes out to five characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.spark.co.nz/cwa/openam/SSORedirect/metaAlias/Xtramail/idp1?SAMLRequest=hZJbbxMxEIX%2Fysrvu95tbsVKIrlJK0UqUCWAEC%2BV60xVq77hme0Wfj32BlB4KU%2B2ZuZoznfsJSpno5A9Pfk9fO8BqXp11qMYGyvWJy%2BCQoPCKwcoSIuDfH8rLppWxBQo6GDZmeRthUKERCZ4Vu22K3Z%2FOZ8uJtfdYvFuItvNTMrJQl5dzW9mc9nl25RVXyBhnl%2BxLM8ixB52Hkl5yqX2Yl63s7qbfWo70V2K6eQbq7aZwXhFo%2BqJKKLgfBiGBqNKz40Ojf%2FJ9aB4iJAd8sPh4x6OJoEm7oCUtEYh%2F0pJOWUsN8fYsWoTPELZ%2BRadPg0J3aeUz9q4aI02xKqbkDSMIa%2FYo7IIBeUup2Fe4G9F%2FgmnLOsdpAOkF6Ph8%2F72DAQeiq3mNfv7zeLA2uB5DEh7wFhMsPWyPIYY80prFSP2hqAuxZqGtOTn7eXpE3zIQLvtXciefxTHTv2Ht1TMsX4cR0U25NFk7kySDQ2bBIoyHaUeGF%2BfVv771da%2FAA%3D%3D&RelayState=https%3A%2F%2Fwebmail.xtra.co.nz%2Findex.cgi&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=LvrAmYCV5hBC0DVOTTpy6cNljal4%2F%2Bder6mZ3Omr%2FRyhpzzmijxyj%2FYRjPz8Aa%2BTTqdHWxB89RHk4nPautUdLz5otiFTu%2Fit4tdu8ET0tdzrplgFTi6oOqvzRZEE7G%2B1WnBMM7ayzO9USqB4UYHOW%2F5AuXqqKB5iYi%2B3E%2BzBMD3Ws3fP3rB%2F86YTLq2zoOrMXygezwPTaek5R2hD0lWmR%2BrlnQtcEMJdPzn1iNmc%2Fz%2Fys8fPtApJ5%2BQXBJMMBHtREa1TI0Iloa05aI2OY66JGqpPonwybqyUzy0pD9WYxf%2Bqq8eLyWp2v5q%2BCbZXdevC%2F2S5GA86YzoPBlwDvDQsiw%3D%3D

Page Load Overview

5.81s
Total Load Time
20
HTTP Requests
3
Domains
164 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:54%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:54%
Script Type:Latin
Text Length:187 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical29% confidence
Type: spa
Method: ml+structural

All Detected Categories

healthcare medical
29%
technology software
27%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
866.22.91.48Auckland, Auckland, New Zealand
AS48851Radware Ltd
666.22.91.1Auckland, Auckland, New Zealand
AS48851Radware Ltd
634.160.81.0Kansas City, Missouri, United States
AS396982Google LLC
203--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17F63C7DA1530A28815CFE54FDF6FEEC8101B605BE8A2D5C1BAED8B0C5B8BAD4FD41844

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:uYfgO/fvJfA5kMNKZoBz7qawqh0QKoZCktWnBo2rTbFDqJuK+v5qwqK7a3ElP3:us/VRkr7qa1ZI42rZ70HK7a3Elf

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:69956:esCEmC2IA5iHBQSggChQMehSEgDSYBMdBAKCBTArAQAJAAARQKSQAkVCHACAuoGFgAqwItgEA/KACXUaEQcwDosIQCFXKGJQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1018181818180000
Perceptual Hash:8dc877227626dc27
Difference Hash:b2b2b2b2b3b34326
Wavelet Hash:18181819191b83c7
Color Hash:#e07d6c

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data