Security Scan Report: www.spark.co.nz

Redirected to:
https://signin.spark.co.nz/?goto=https://www.spark.co.nz/xtramail/chec...
Site favicon
Submitted: May 14, 2026, 5:31:37 PMCompleted: May 14, 2026, 5:33:37 PMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 2 domains to perform 14 HTTP transactions. The main domain is signin.spark.co.nz.

Submitted URL: https://www.spark.co.nz/cwa/openam/SSORedirect/metaAlias/Xtramail/idp1?SAMLRequest=hZLdThsxEIVfZeX7XWeTQFMribRkEykSbVFCK8QNMs4gLPyHZ5alfXrsDVTpDb2yNDNHc77jmaO0Joimo0e3g%2BcOkIpXaxyKobFgXXTCS9QonLSAgpTYN98uxbgaiRA9eeUNO5F8rpCIEEl7x4ptu2B3q4t6vWnaSbuaTafjetS055v1etN%2BnbXTelbPWPELIqb5BUvyJELsYOuQpKNUGo3Py9FZWU%2Bv6y9iUovJ2S0r2sSgnaRB9UgUUHDe932FQcanSvnK%2FeGql9wHSA75fv9jBwcdQRG3QLIxWiK%2FoSit1IbrQ6hZsfIOIe%2F8jE4dh4TqYkxvqW0wWmlixcZHBUPIC%2FYgDUJGuUpp6Bf4W2k%2BwsnLOgtxD%2FFFK%2Fi5uzwBgftsq3pN%2Ft5ZLBjjHQ8eaQcYsgm2nOfPEENecSlDwE4TlLlYUh%2Fn%2FLQ9Px7B9wS0ba988vw7O7byP7y5og%2FlwzAqkiGHOnEnkmSoX0WQlOgodsD48rjy31NbvgE%3D&RelayState=https%3A%2F%2Fwebmail.xtra.co.nz%2Findex.cgi&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=p4YwPUjg0suFafEvIzwSLd%2BbtbEfKRVm2Jd8G5wxwr5ewB82SpTwhZUuDhZT6sDvN3KLk3XkPItlKYwQXW16vln4z3ZKm6tCIzk%2BcakNASKahhPcp12NgnBBeqsJSuOinnde2p8U5j7VjzhI%2Bc4bTQSsTU%2BTSzcDANYCJp%2F55qqSjsu4hTtqNmq0lWZJLcv0w9NqZSbiT8muo1RHq06hKH5qIje5uEE52j46fkInBAGTHyyjH6NXU%2Ba11Vv1g0F8pgQCFFSZ16bpX7RokWAlaNZ4Q%2FGXi0tzesPcAUtv09%2F3ZB77OxEdXvbiYNmpaGKGH05pf0b0fdpEx1paTtZi2A%3D%3D

Effective URL: https://signin.spark.co.nz/?goto=https://www.spark.co.nz/xtramail/checkcookies?spEntityID%3Dappsuite-saml-twr%26goto%3Dhttp://openam.internal.spark.co.nz:8080/openam/saml2/continue/metaAlias/Xtramail/idp1?secondVisitUrl%253D/SSORedirect/metaAlias/Xtramail/idp1?ReqID%25253D_CB1EFAD3DC844210AD6FEEFD98D41818%26AMAuthCookie%3D&brand=xtramailRedirected

The Cisco Umbrella rank of the primary domain is #416,869 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 92%

10
Risk Score

High‑risk site mimicking Xtra Mail login; unknown age, low ranking, and critical IDS alerts suggest phishing/malware. Avoid and report.

Risk Factors
Low Cisco Umbrella ranking for a well‑known brand domain
Unknown domain age combined with brand impersonation
Critical IDS alerts for malware/C2 activity
High JavaScript obfuscation score
Single login form collecting credentials
Domain age information unavailable

Details

Page Title

Sign in

Scan Type

public

Language

🇺🇸

English

(54% confidence)

Category

healthcare medical

(29%)

Domain Information

The domain name 'www.spark.co.nz' uses the New Zealand country-code top-level domain (.co.nz) with subdomain 'www'. The registrable portion 'spark' spans 5 characters holding one vowel versus 4 consonants. It segments into 1 word: spark. Average segment length settles at 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.spark.co.nz/cwa/openam/SSORedirect/metaAlias/Xtramail/idp1?SAMLRequest=hZLdThsxEIVfZeX7XWeTQFMribRkEykSbVFCK8QNMs4gLPyHZ5alfXrsDVTpDb2yNDNHc77jmaO0Joimo0e3g%2BcOkIpXaxyKobFgXXTCS9QonLSAgpTYN98uxbgaiRA9eeUNO5F8rpCIEEl7x4ptu2B3q4t6vWnaSbuaTafjetS055v1etN%2BnbXTelbPWPELIqb5BUvyJELsYOuQpKNUGo3Py9FZWU%2Bv6y9iUovJ2S0r2sSgnaRB9UgUUHDe932FQcanSvnK%2FeGql9wHSA75fv9jBwcdQRG3QLIxWiK%2FoSit1IbrQ6hZsfIOIe%2F8jE4dh4TqYkxvqW0wWmlixcZHBUPIC%2FYgDUJGuUpp6Bf4W2k%2BwsnLOgtxD%2FFFK%2Fi5uzwBgftsq3pN%2Ft5ZLBjjHQ8eaQcYsgm2nOfPEENecSlDwE4TlLlYUh%2Fn%2FLQ9Px7B9wS0ba988vw7O7byP7y5og%2FlwzAqkiGHOnEnkmSoX0WQlOgodsD48rjy31NbvgE%3D&RelayState=https%3A%2F%2Fwebmail.xtra.co.nz%2Findex.cgi&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=p4YwPUjg0suFafEvIzwSLd%2BbtbEfKRVm2Jd8G5wxwr5ewB82SpTwhZUuDhZT6sDvN3KLk3XkPItlKYwQXW16vln4z3ZKm6tCIzk%2BcakNASKahhPcp12NgnBBeqsJSuOinnde2p8U5j7VjzhI%2Bc4bTQSsTU%2BTSzcDANYCJp%2F55qqSjsu4hTtqNmq0lWZJLcv0w9NqZSbiT8muo1RHq06hKH5qIje5uEE52j46fkInBAGTHyyjH6NXU%2Ba11Vv1g0F8pgQCFFSZ16bpX7RokWAlaNZ4Q%2FGXi0tzesPcAUtv09%2F3ZB77OxEdXvbiYNmpaGKGH05pf0b0fdpEx1paTtZi2A%3D%3D

Page Load Overview

1.03s
Total Load Time
14
HTTP Requests
2
Domains
N/A
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:54%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:54%
Script Type:Latin
Text Length:187 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical29% confidence
Type: spa
Method: ml+structural

All Detected Categories

healthcare medical
29%
technology software
27%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
766.22.91.48Auckland, Auckland, New Zealand
AS48851Radware Ltd
766.22.91.1Auckland, Auckland, New Zealand
AS48851Radware Ltd
142--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19163C7DA1530A28815CFE54EDF6FEEC8105B605BE8A2D5C1BAED8B0C5B8BED4FD41844

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:uGgO/fvJfAwkANKZoBz7qawqh0QKoZCktWnBo2rTbFDqJuKjv5qwqI2NDolP3:uo/VIYr7qa1ZI42rZC0HI2NDolf

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:70624:AEAayAAAKyKCAEA4io4NCsRChJRBJRMACisEM6AigJMGABIAjtqlC1QdBEAjNIO4IDCAQhdOBVgANIkHJFQABFEAMRSdGzgJ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1018181818180000
Perceptual Hash:8dc877227626dc27
Difference Hash:b2b2b2b2b3b34326
Wavelet Hash:18181819191b83c7
Color Hash:#93611f

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data