Security Scan Report: www.spark.co.nz

Redirected to:
https://signin.spark.co.nz/?goto=https://www.spark.co.nz/xtramail/chec...
Site favicon
Submitted: May 16, 2026, 9:02:46 PMCompleted: May 16, 2026, 9:04:29 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 2 countries across 3 domains to perform 20 HTTP transactions. The main domain is signin.spark.co.nz.

Submitted URL: https://www.spark.co.nz/cwa/openam/SSORedirect/metaAlias/Xtramail/idp1?SAMLRequest=hZLRa9swEMb%2FFaN3W5ZpvVQkAddpIdBtJenG6EvRlCsVkyVNd667%2FfWTnHVkL%2B2T4O4%2B7vt9uiWqwQbZjfTkdvBzBKTiZbAO5dxYsTE66RUalE4NgJK03Hcfb2RT1TJET157y04kbysUIkQy3rFiu1mxhzPRNUL07dWluOgX4rIVi2vR1xetqD%2FUm%2BaKFV8hYppfsSRPIsQRtg5JOUqlumnL%2BrwU7V0jZN1IsbhnxSYxGKdoVj0RBZScT9NUYVDxR6V95X5zPSnuAySHfL%2F%2FvIODiaCJD0Cqs0Yh%2F0ZRDcpYbg5BsKL3DiHvfItOH4ekHmNMb2mGYI02xIprHzXMIa%2FYo7IIGeU2pWGe4V%2Blew0nLxsHiHuIz0bDl93NCQh8z7aql%2BTvL8sA1nrHg0faAYZsgq2X%2BTPknFdcqxBwNARlLpY0xSU%2FbS%2BPR%2FApAW03tz55%2FpUdD%2Bod3lwxh%2FJxHpXJkEOTuBNJMjT1ERQlOoojML4%2Brvz%2F1NZ%2FAA%3D%3D&RelayState=https%3A%2F%2Fwebmail.xtra.co.nz%2Findex.cgi&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=eRz0grX%2FYHLSmkTqFneQdBUFdxFMQnwpH%2F5LYqlqKUgNJLzHPgh4kHuoophJWGHUtMU5hrxjE7eHkerP%2B7GWvwYn8GiU%2BzU%2Bc6%2BauRxl%2F4aWNz3Ca5Qv8uXLk0%2FRFAmUgF2bYlHb2y1VCo3xCO7SefpfyHYi%2BLwZpEyEAdEL%2FpffioQvU9RDwUgESC349sosgite2M2toBTt9fEqAfBstfSn1JlcT7QKPk9%2BuHsjJHc4%2Ba%2FQnmIq110ErXXam6%2BIL32LPAxjs1zfI7IkLGzMfgFTIf9RJbwR528PawJjOE%2Fh6KxaHTNEr0zye0RktQiZOEAsDgE6pM2VZduL8rSxnQ%3D%3D

Effective URL: https://signin.spark.co.nz/?goto=https://www.spark.co.nz/xtramail/checkcookies?spEntityID%3Dappsuite-saml-twr%26goto%3Dhttp://openam.internal.spark.co.nz:8080/openam/saml2/continue/metaAlias/Xtramail/idp1?secondVisitUrl%253D/SSORedirect/metaAlias/Xtramail/idp1?ReqID%25253D_41A211C6EB19C81B618F1C0961070D2E%26AMAuthCookie%3D&brand=xtramailRedirected

The Cisco Umbrella rank of the primary domain is #416,869 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 92%

10
Risk Score

The site presents a login page for Xtra Mail on a low‑rank, unknown‑age domain with many critical IDS alerts and heavy JS obfuscation, indicating high risk of credential phishing.

Risk Factors
Low domain ranking for a claimed brand
Domain age unknown (treated as new)
Multiple Critical IDS alerts (malware, potential C2)
High JavaScript obfuscation and use of Function() constructor
Credential collection on a site with suspicious indicators
Domain age information unavailable

Details

Page Title

Sign in

Scan Type

public

Language

🇺🇸

English

(54% confidence)

Category

healthcare medical

(29%)

Domain Information

Within the New Zealand country-code top-level domain (.co.nz), 'www.spark.co.nz' is registered, featuring subdomain 'www'. The second-level label 'spark' is 5 characters long with one vowel and four consonants. Breaking it apart gives one word: spark. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.spark.co.nz/cwa/openam/SSORedirect/metaAlias/Xtramail/idp1?SAMLRequest=hZLRa9swEMb%2FFaN3W5ZpvVQkAddpIdBtJenG6EvRlCsVkyVNd667%2FfWTnHVkL%2B2T4O4%2B7vt9uiWqwQbZjfTkdvBzBKTiZbAO5dxYsTE66RUalE4NgJK03Hcfb2RT1TJET157y04kbysUIkQy3rFiu1mxhzPRNUL07dWluOgX4rIVi2vR1xetqD%2FUm%2BaKFV8hYppfsSRPIsQRtg5JOUqlumnL%2BrwU7V0jZN1IsbhnxSYxGKdoVj0RBZScT9NUYVDxR6V95X5zPSnuAySHfL%2F%2FvIODiaCJD0Cqs0Yh%2F0ZRDcpYbg5BsKL3DiHvfItOH4ekHmNMb2mGYI02xIprHzXMIa%2FYo7IIGeU2pWGe4V%2Blew0nLxsHiHuIz0bDl93NCQh8z7aql%2BTvL8sA1nrHg0faAYZsgq2X%2BTPknFdcqxBwNARlLpY0xSU%2FbS%2BPR%2FApAW03tz55%2FpUdD%2Bod3lwxh%2FJxHpXJkEOTuBNJMjT1ERQlOoojML4%2Brvz%2F1NZ%2FAA%3D%3D&RelayState=https%3A%2F%2Fwebmail.xtra.co.nz%2Findex.cgi&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=eRz0grX%2FYHLSmkTqFneQdBUFdxFMQnwpH%2F5LYqlqKUgNJLzHPgh4kHuoophJWGHUtMU5hrxjE7eHkerP%2B7GWvwYn8GiU%2BzU%2Bc6%2BauRxl%2F4aWNz3Ca5Qv8uXLk0%2FRFAmUgF2bYlHb2y1VCo3xCO7SefpfyHYi%2BLwZpEyEAdEL%2FpffioQvU9RDwUgESC349sosgite2M2toBTt9fEqAfBstfSn1JlcT7QKPk9%2BuHsjJHc4%2Ba%2FQnmIq110ErXXam6%2BIL32LPAxjs1zfI7IkLGzMfgFTIf9RJbwR528PawJjOE%2Fh6KxaHTNEr0zye0RktQiZOEAsDgE6pM2VZduL8rSxnQ%3D%3D

Page Load Overview

11.12s
Total Load Time
20
HTTP Requests
3
Domains
164 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:54%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:54%
Script Type:Latin
Text Length:187 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical29% confidence
Type: spa
Method: ml+structural

All Detected Categories

healthcare medical
29%
technology software
27%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
866.22.91.1Auckland, Auckland, New Zealand
AS48851Radware Ltd
666.22.91.48Auckland, Auckland, New Zealand
AS48851Radware Ltd
634.160.81.0Kansas City, Missouri, United States
AS396982Google LLC
203--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19763C7DA1530A24815CFE54FDF6FEEC8105B605BE8A2D5C1BAEE8B0C5B8BAD4FD41444

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:uBgO/fvJfAwkkNKZoBz7qawqh0QKoZCktWnBo2rTbFDqJuKFv5qwqI2tDolP3:u//VIcr7qa1ZI42rZW0HI2tDolf

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:70628:IFAoKDcAKKDiACY8LxIDDmBEAIoAGRugSCFgYSAwwxWAJTgAsWGJJTklhULiDIAOUJypIgoIY0ECUFA+EFhCDcBMeB6lBhxA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1018181818180000
Perceptual Hash:8dc877227626dc27
Difference Hash:b2b2b2b2b3b34326
Wavelet Hash:18181819191b83c7
Color Hash:#798cd2

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data