Security Scan Report: www.spark.co.nz

Redirected to:
https://signin.spark.co.nz/?goto=https://www.spark.co.nz/xtramail/chec...
Site favicon
Submitted: May 15, 2026, 10:48:54 PMCompleted: May 15, 2026, 10:50:29 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 2 countries across 3 domains to perform 20 HTTP transactions. The main domain is signin.spark.co.nz.

Submitted URL: https://www.spark.co.nz/cwa/openam/SSORedirect/metaAlias/Xtramail/idp1?SAMLRequest=hZLdjtMwEIVfJfJ94ia0JbXaSmmjSpUWWLWAEDfIuLNaC%2F%2FhmWwWnh47BVRulitLM3M05zueNUprgugGenQn%2BD4AUvFsjUMxNTZsiE54iRqFkxZQkBLn7s2daKqZCNGTV96wG8nLCokIkbR3rDj2G%2FZltdsdDs28X%2FavV03btou6ftXt63m963btctmw4iNETPMbluRJhDjA0SFJR6k0a5blbFHWi%2FdNI%2BatmK8%2Bs6JPDNpJmlSPRAEF5%2BM4Vhhk%2FFYpX7mfXI2S%2BwDJIT%2Bf353goiMo4hZIdkZL5J8oSiu14foSalbsvUPIO1%2BiU9choYYY01tqG4xWmlhx8FHBFPKGPUiDkFHuUxr6Cf5Wuj%2Fh5GWDhXiG%2BKQVfDjd3YDA12yrek7%2BfrNYMMY7HjzSCTBkE2y7zp8hprziVoaAgyYoc7GkMa75bXt9PYK3CejY3%2Fvk%2BUd2bOV%2FeHNFX8qHaVQkQw514k4kydC4jyAp0VEcgPHtdeW%2Fp7b9BQ%3D%3D&RelayState=https%3A%2F%2Fwebmail.xtra.co.nz%2Findex.cgi&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=o13gdbmBZt9mBQoU8RMum%2FlkSVaP2JyqG8g%2FPPlKNo9%2FA5%2Bt2uw1aQB88JI%2Bvdf7e3QQ3fOCo1wAFkQkpt37oMqnazcI9Z6QZNyKARHKupH6lLjLgmOJlsP728QmtvfgdWsOMWjxrPImUl7zBQDWSjZUReD3x9w3E27CkyuajiSJaa3goQNVzY25zGINPuNQ9aYEke3fSa4tbLgwK5lfx9y2nLvnWUMNhFzaiTeZUUfafBzIRCrNQJs2LquyeAX1%2F5zHnvAWB8tMPnBhX7tr9Y5hH3DnlFbXyO71dSKvPxrIPJFYWGckc2qdtVh2hlKKivop2QWb9JnnFc7x%2FVp4SQ%3D%3D

Effective URL: https://signin.spark.co.nz/?goto=https://www.spark.co.nz/xtramail/checkcookies?spEntityID%3Dappsuite-saml-twr%26goto%3Dhttp://openam.internal.spark.co.nz:8080/openam/saml2/continue/metaAlias/Xtramail/idp1?secondVisitUrl%253D/SSORedirect/metaAlias/Xtramail/idp1?ReqID%25253D_9BBFF24D6D7928885113AC141BAB8662%26AMAuthCookie%3D&brand=xtramailRedirected

The Cisco Umbrella rank of the primary domain is #416,869 of the top 1 million websites

AI Security Verdict

Confirmed Scam

Confidence: 93%

9
Risk Score

The site hosts a credential‑phishing login for Xtra Mail, flagged by multiple critical IDS alerts and low domain reputation, indicating a confirmed scam.

Risk Factors
Critical IDS alerts indicating malware data exfiltration and command‑and‑control activity
Credential collection form on a newly‑registered/unknown‑age domain
Low domain reputation for a brand‑impersonating page
Potential brand impersonation (Xtra Mail) on a low‑ranked domain
Domain age information unavailable

Details

Page Title

Sign in

Scan Type

public

Language

🇺🇸

English

(54% confidence)

Category

healthcare medical

(29%)

Domain Information

You're looking at domain 'www.spark.co.nz' on the New Zealand country-code top-level domain (.co.nz) and includes subdomain 'www'. The registrable portion 'spark' spans 5 characters split between one vowel and 4 consonants. Tokenizing the label suggests one word: spark. Expect 5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.spark.co.nz/cwa/openam/SSORedirect/metaAlias/Xtramail/idp1?SAMLRequest=hZLdjtMwEIVfJfJ94ia0JbXaSmmjSpUWWLWAEDfIuLNaC%2F%2FhmWwWnh47BVRulitLM3M05zueNUprgugGenQn%2BD4AUvFsjUMxNTZsiE54iRqFkxZQkBLn7s2daKqZCNGTV96wG8nLCokIkbR3rDj2G%2FZltdsdDs28X%2FavV03btou6ftXt63m963btctmw4iNETPMbluRJhDjA0SFJR6k0a5blbFHWi%2FdNI%2BatmK8%2Bs6JPDNpJmlSPRAEF5%2BM4Vhhk%2FFYpX7mfXI2S%2BwDJIT%2Bf353goiMo4hZIdkZL5J8oSiu14foSalbsvUPIO1%2BiU9choYYY01tqG4xWmlhx8FHBFPKGPUiDkFHuUxr6Cf5Wuj%2Fh5GWDhXiG%2BKQVfDjd3YDA12yrek7%2BfrNYMMY7HjzSCTBkE2y7zp8hprziVoaAgyYoc7GkMa75bXt9PYK3CejY3%2Fvk%2BUd2bOV%2FeHNFX8qHaVQkQw514k4kydC4jyAp0VEcgPHtdeW%2Fp7b9BQ%3D%3D&RelayState=https%3A%2F%2Fwebmail.xtra.co.nz%2Findex.cgi&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=o13gdbmBZt9mBQoU8RMum%2FlkSVaP2JyqG8g%2FPPlKNo9%2FA5%2Bt2uw1aQB88JI%2Bvdf7e3QQ3fOCo1wAFkQkpt37oMqnazcI9Z6QZNyKARHKupH6lLjLgmOJlsP728QmtvfgdWsOMWjxrPImUl7zBQDWSjZUReD3x9w3E27CkyuajiSJaa3goQNVzY25zGINPuNQ9aYEke3fSa4tbLgwK5lfx9y2nLvnWUMNhFzaiTeZUUfafBzIRCrNQJs2LquyeAX1%2F5zHnvAWB8tMPnBhX7tr9Y5hH3DnlFbXyO71dSKvPxrIPJFYWGckc2qdtVh2hlKKivop2QWb9JnnFc7x%2FVp4SQ%3D%3D

Page Load Overview

5.66s
Total Load Time
20
HTTP Requests
3
Domains
164 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:54%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:54%
Script Type:Latin
Text Length:187 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical29% confidence
Type: spa
Method: ml+structural

All Detected Categories

healthcare medical
29%
technology software
27%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
866.22.91.1Auckland, Auckland, New Zealand
AS48851Radware Ltd
666.22.91.48Auckland, Auckland, New Zealand
AS48851Radware Ltd
634.160.81.0Kansas City, Missouri, United States
AS396982Google LLC
203--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E763C7DA1530A24815CFE54EEF6FEEC8105B605BE8A3D5C1BAED8B0C5B8BAD4FD41844

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:uj0gO/fvJfAwk6NKZoBz7qawqh0QKoZCktWnBo2rTbFDqJuKcv5qwqI2IDolP3:uy/VI6r7qa1ZI42rZn0HI2IDolf

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:70628:AG6qOAYCIAhgAkSxJXJyAKmGLBVVSkECSAGQQornw1GSHTABgMtlBiUUAEokAiKJFTChIYQIhAHTUGCUVEICyCSIYkvkpBBY

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1018181818180000
Perceptual Hash:8dc877227626dc27
Difference Hash:b2b2b2b2b3b34326
Wavelet Hash:18181819191b83c7
Color Hash:#bf4095

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data