Security Scan Report: www.spark.co.nz

Redirected to:
https://signin.spark.co.nz/?goto=https://www.spark.co.nz/xtramail/chec...
Site favicon
Submitted: May 14, 2026, 9:47:31 PMCompleted: May 14, 2026, 9:49:06 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 2 countries across 3 domains to perform 20 HTTP transactions. The main domain is signin.spark.co.nz.

Submitted URL: https://www.spark.co.nz/cwa/openam/SSORedirect/metaAlias/Xtramail/idp1?SAMLRequest=hZLdahsxEIVfZdH9ruzFdrCwDeu1A4YkDXZbQm6CKk%2BIqP6qmc2mefpI66Y4N8mFEMzMYc53pAVKa4JoOnpye%2FjTAVLxYo1DMTSWrItOeIkahZMWUJASh%2Bb6StTVSIToyStv2Jnkc4VEhEjaO1bsNkv20LTttl6vL2ez7XbdzueTej2fNZOLepzOdjplxU%2BImOaXLMmTCLGDnUOSjlJpVM%2FK0bQcT77XYzG5EPX8nhWbxKCdpEH1RBRQcN73fYVBxt%2BV8pV75aqX3AdIDvnh8G0PRx1BEbdAsjFaIr%2BjKK3UhutjGLOi9Q4h7%2FyMTp2GhOpiTHepbTBaaWLFpY8KhpCX7FEahIxym9LQz%2FC%2F0ryHk5d1FuIB4rNW8GN%2FdQYCv7Kt6iX5%2B8diwRjvePBIe8CQTbDVIj%2BGGPKKKxkCdpqgzMWS%2Brjg5%2B3F6RPcJKDd5tYnz3%2BzYyu%2F4M0VfSwfh1GRDDnUiTuRJEN9G0FSoqPYAeOr08qPX231Bg%3D%3D&RelayState=https%3A%2F%2Fwebmail.xtra.co.nz%2Findex.cgi&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=LN7hUS8HFfmMvDSvTF7h1WEZRTOrmsNEKQFJiS%2BZ7mYepfH%2BNdw4kxieSzIbCgqMtb4ne10YWbde6bOeg7bYPL7a46FIK3qEE55YGXavtZZxXmLidYozH70SQQZpoPtTa4gcLEg%2BxM%2FIKxbztghJ47W66B17TQ0qVHOMY4B1%2FkZw9SvCH0UaBTzqU6RDHXDNi%2BnrP3%2Bo%2BKKy%2FG%2BDDWGaiSwez5sPN0l50DuVi2t8K0ZEv6ReyuCNMCBuR6nGzoDYeUCSuxR%2Bx3jiyV%2FOdGEVhbKLjcAoDzlitRFLEvClxL0kxdlheeDkz9aa%2BK32HrTXYEv42CHm2teJrUola1ltHQ%3D%3D

Effective URL: https://signin.spark.co.nz/?goto=https://www.spark.co.nz/xtramail/checkcookies?spEntityID%3Dappsuite-saml-twr%26goto%3Dhttp://openam.internal.spark.co.nz:8080/openam/saml2/continue/metaAlias/Xtramail/idp1?secondVisitUrl%253D/SSORedirect/metaAlias/Xtramail/idp1?ReqID%25253D_ACCE2BBF66EEBC9942B96A4721472E55%26AMAuthCookie%3D&brand=xtramailRedirected

The Cisco Umbrella rank of the primary domain is #416,869 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 82%

10
Risk Score

The site presents a credential login for Xtra Mail on a low‑rank, unknown‑age domain with multiple critical IDS alerts and heavily obfuscated JavaScript, indicating a high‑risk phishing attempt.

Risk Factors
Unknown domain age with brand impersonation
Critical IDS alerts for malware and data exfiltration
Highly obfuscated JavaScript
Low Cisco Umbrella ranking for a claimed reputable brand
Login form collecting email and password
Domain age information unavailable

Details

Page Title

Sign in

Scan Type

public

Language

🇺🇸

English

(54% confidence)

Category

healthcare medical

(29%)

Domain Information

You're looking at domain 'www.spark.co.nz' on the New Zealand country-code top-level domain (.co.nz), featuring subdomain 'www'. Its registrable label 'spark' stretches across 5 characters split between one vowel and 4 consonants. Word splitting yields 1 word: spark. Average segment length settles at 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.spark.co.nz/cwa/openam/SSORedirect/metaAlias/Xtramail/idp1?SAMLRequest=hZLdahsxEIVfZdH9ruzFdrCwDeu1A4YkDXZbQm6CKk%2BIqP6qmc2mefpI66Y4N8mFEMzMYc53pAVKa4JoOnpye%2FjTAVLxYo1DMTSWrItOeIkahZMWUJASh%2Bb6StTVSIToyStv2Jnkc4VEhEjaO1bsNkv20LTttl6vL2ez7XbdzueTej2fNZOLepzOdjplxU%2BImOaXLMmTCLGDnUOSjlJpVM%2FK0bQcT77XYzG5EPX8nhWbxKCdpEH1RBRQcN73fYVBxt%2BV8pV75aqX3AdIDvnh8G0PRx1BEbdAsjFaIr%2BjKK3UhutjGLOi9Q4h7%2FyMTp2GhOpiTHepbTBaaWLFpY8KhpCX7FEahIxym9LQz%2FC%2F0ryHk5d1FuIB4rNW8GN%2FdQYCv7Kt6iX5%2B8diwRjvePBIe8CQTbDVIj%2BGGPKKKxkCdpqgzMWS%2Brjg5%2B3F6RPcJKDd5tYnz3%2BzYyu%2F4M0VfSwfh1GRDDnUiTuRJEN9G0FSoqPYAeOr08qPX231Bg%3D%3D&RelayState=https%3A%2F%2Fwebmail.xtra.co.nz%2Findex.cgi&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=LN7hUS8HFfmMvDSvTF7h1WEZRTOrmsNEKQFJiS%2BZ7mYepfH%2BNdw4kxieSzIbCgqMtb4ne10YWbde6bOeg7bYPL7a46FIK3qEE55YGXavtZZxXmLidYozH70SQQZpoPtTa4gcLEg%2BxM%2FIKxbztghJ47W66B17TQ0qVHOMY4B1%2FkZw9SvCH0UaBTzqU6RDHXDNi%2BnrP3%2Bo%2BKKy%2FG%2BDDWGaiSwez5sPN0l50DuVi2t8K0ZEv6ReyuCNMCBuR6nGzoDYeUCSuxR%2Bx3jiyV%2FOdGEVhbKLjcAoDzlitRFLEvClxL0kxdlheeDkz9aa%2BK32HrTXYEv42CHm2teJrUola1ltHQ%3D%3D

Page Load Overview

6.28s
Total Load Time
20
HTTP Requests
3
Domains
164 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:54%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:54%
Script Type:Latin
Text Length:187 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical29% confidence
Type: spa
Method: ml+structural

All Detected Categories

healthcare medical
29%
technology software
27%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
866.22.91.1Auckland, Auckland, New Zealand
AS48851Radware Ltd
634.160.81.0Kansas City, Missouri, United States
AS396982Google LLC
666.22.91.48Auckland, Auckland, New Zealand
AS48851Radware Ltd
203--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11F63C7DA1530A24815DFE54EDF6FEEC8101B605BE8A2D5C1BAEE8B0C5B8BED4FD41844

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:ucgO/fvJfAwk7NKZoBz7qawqh0QKoZCktWnBo2rTbFDqJuKdv5qwqI7tOolP3:uW/VIRr7qa1ZI42rZG0HI7tOolf

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:70628:R0ADmQQAOBTBRQAAYAURDFSEGoFjjXEISMOiIGEwQYwmIAK8EMTBDxCooyoYgkQFAhWgopGAj4ugBhJJAGAjgq8AAPKCIDgo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1018181818180000
Perceptual Hash:8dc877227626dc27
Difference Hash:b2b2b2b2b3b34326
Wavelet Hash:18181819191b83c7
Color Hash:#d22dba

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data