Security Scan Report: www.spark.co.nz

Redirected to:
https://signin.spark.co.nz/?goto=https://www.spark.co.nz/xtramail/chec...
Site favicon
Submitted: May 15, 2026, 4:23:21 PMCompleted: May 15, 2026, 4:25:36 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 2 countries across 3 domains to perform 20 HTTP transactions. The main domain is signin.spark.co.nz.

Submitted URL: https://www.spark.co.nz/cwa/openam/SSORedirect/metaAlias/Xtramail/idp1?SAMLRequest=hZLdbtswDIVfxdC9rdhd0lZIAjg2CgTotiLphqE3haqwqDD9TaTrbk8%2FyWmH7Ka9EkDygOc74hKlNUG0Az25HfwaAKl4scahmBorNkQnvESNwkkLKEiJffv5WjTVTIToyStv2InkfYVEhEjaO1Zs%2BxW7b%2Bqu31zMm3bR9O3Fp%2FNFtznv5nXfb5rLTX12xYrvEDHNr1iSJxHiAFuHJB2l0qxZlLN5Wc9v64VozkR9eceKPjFoJ2lSPREFFJyP41hhkPFnpXzl%2FnA1Su4DJId8v%2F%2B6g4OOoIhbINkaLZH%2FoCit1IbrQ6hZ0XmHkHe%2BR6eOQ0INMaa31DYYrTSx4spHBVPIK%2FYoDUJGuUlp6Gf4V2nfwsnLBgtxD%2FFZK%2Fi2uz4BgYdsq3pJ%2Fl5ZLBjjHQ8eaQcYsgm2XubPEFNecS1DwEETlLlY0hiX%2FLS9PB7BlwS07W988vw7O7byA95c0YfycRoVyZBDnbgTSTI0dhEkJTqKAzC%2BPq78%2F9TWfwE%3D&RelayState=https%3A%2F%2Fwebmail.xtra.co.nz%2Findex.cgi&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=ijf0WKB%2BcjdOEXAqXd8rcdUiHCstuHBH%2F6EPu%2B%2FHyY4G36Sh8idf8UC2vSm%2BJaSfjs0gVijGgZvef6RmY837K6bgVXRCkmgXs5gbGuFePYBoBfCokaI99J4alvw7VSg1woBGGRi7varN7W%2F6%2BH7oP76ssZ4ggYNGP3QVDXhJwubWh1m9v0aEjgI7KFt2PL5BYy47FU%2ByJWLSyDlBdQHl%2Bp0W8T9U1xOoDtK7sDOrkDcFidrsacKQROECa1%2FRM4N1immDSg79PgQopBU6l3SSzMI3IifjkYKZsG%2FfCrId7PsQtU9h42x4ofniWA3RaSsn451GqY%2FSbBKZvI32QP8jEg%3D%3D

Effective URL: https://signin.spark.co.nz/?goto=https://www.spark.co.nz/xtramail/checkcookies?spEntityID%3Dappsuite-saml-twr%26goto%3Dhttp://openam.internal.spark.co.nz:8080/openam/saml2/continue/metaAlias/Xtramail/idp1?secondVisitUrl%253D/SSORedirect/metaAlias/Xtramail/idp1?ReqID%25253D_21CDB852A62DA8476CB7C51DDB29B13F%26AMAuthCookie%3D&brand=xtramailRedirected

The Cisco Umbrella rank of the primary domain is #416,869 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 86%

10
Risk Score

The site presents a credential login for Xtra Mail on a low‑rank, unknown‑age domain and triggers multiple critical IDS alerts, indicating high‑risk phishing activity.

Risk Factors
Low Cisco Umbrella ranking for a claimed brand
Unknown domain age with credential collection
Critical IDS alerts for malware and possible command‑and‑control
Credential form on a domain that does not appear in top rankings
Potential brand impersonation (Xtra Mail) on a low‑rank domain
Domain age information unavailable

Details

Page Title

Sign in

Scan Type

public

Language

🇺🇸

English

(54% confidence)

Category

healthcare medical

(29%)

Domain Information

Within the New Zealand country-code top-level domain (.co.nz), 'www.spark.co.nz' is registered, featuring subdomain 'www'. The registrable portion 'spark' spans 5 characters with one vowel and four consonants. Tokenizing the label suggests 1 word: spark. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.spark.co.nz/cwa/openam/SSORedirect/metaAlias/Xtramail/idp1?SAMLRequest=hZLdbtswDIVfxdC9rdhd0lZIAjg2CgTotiLphqE3haqwqDD9TaTrbk8%2FyWmH7Ka9EkDygOc74hKlNUG0Az25HfwaAKl4scahmBorNkQnvESNwkkLKEiJffv5WjTVTIToyStv2InkfYVEhEjaO1Zs%2BxW7b%2Bqu31zMm3bR9O3Fp%2FNFtznv5nXfb5rLTX12xYrvEDHNr1iSJxHiAFuHJB2l0qxZlLN5Wc9v64VozkR9eceKPjFoJ2lSPREFFJyP41hhkPFnpXzl%2FnA1Su4DJId8v%2F%2B6g4OOoIhbINkaLZH%2FoCit1IbrQ6hZ0XmHkHe%2BR6eOQ0INMaa31DYYrTSx4spHBVPIK%2FYoDUJGuUlp6Gf4V2nfwsnLBgtxD%2FFZK%2Fi2uz4BgYdsq3pJ%2Fl5ZLBjjHQ8eaQcYsgm2XubPEFNecS1DwEETlLlY0hiX%2FLS9PB7BlwS07W988vw7O7byA95c0YfycRoVyZBDnbgTSTI0dhEkJTqKAzC%2BPq78%2F9TWfwE%3D&RelayState=https%3A%2F%2Fwebmail.xtra.co.nz%2Findex.cgi&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=ijf0WKB%2BcjdOEXAqXd8rcdUiHCstuHBH%2F6EPu%2B%2FHyY4G36Sh8idf8UC2vSm%2BJaSfjs0gVijGgZvef6RmY837K6bgVXRCkmgXs5gbGuFePYBoBfCokaI99J4alvw7VSg1woBGGRi7varN7W%2F6%2BH7oP76ssZ4ggYNGP3QVDXhJwubWh1m9v0aEjgI7KFt2PL5BYy47FU%2ByJWLSyDlBdQHl%2Bp0W8T9U1xOoDtK7sDOrkDcFidrsacKQROECa1%2FRM4N1immDSg79PgQopBU6l3SSzMI3IifjkYKZsG%2FfCrId7PsQtU9h42x4ofniWA3RaSsn451GqY%2FSbBKZvI32QP8jEg%3D%3D

Page Load Overview

5.34s
Total Load Time
20
HTTP Requests
3
Domains
164 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:54%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:54%
Script Type:Latin
Text Length:187 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical29% confidence
Type: spa
Method: ml+structural

All Detected Categories

healthcare medical
29%
technology software
27%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
866.22.91.48Auckland, Auckland, New Zealand
AS48851Radware Ltd
666.22.91.1Auckland, Auckland, New Zealand
AS48851Radware Ltd
634.160.81.0Kansas City, Missouri, United States
AS396982Google LLC
203--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C363C7DA1530A24815CEE54EEF6FEEC8105B605BE8A2D5C17AEE8B0C5B8BED4FD41844

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:uCgO/fvJfAwkFNKZoBz7qawqh0QKoZCktWnBo2rTbFDqJuKEv5qwqIv4KolP3:uM/VIDr7qa1ZI42rZx0HIv4Kolf

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:70623:W1CAiAGJEAUACCAMc4QRpBFIJJKsBQ0AyHPlcEQUMAgQwpAK8QgEEwVxWDKjNZIIocigR4BII6agMBCjEwFMABJAWE5MK8AC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1018181818180000
Perceptual Hash:8dc877227626dc27
Difference Hash:b2b2b2b2b3b34326
Wavelet Hash:18181819191b83c7
Color Hash:#862e2d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data