Security Scan Report: www.spark.co.nz

Redirected to:
https://signin.spark.co.nz/?goto=https://www.spark.co.nz/xtramail/chec...
Site favicon
Submitted: May 14, 2026, 8:58:53 PMCompleted: May 14, 2026, 9:00:30 PMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 2 countries across 3 domains to perform 20 HTTP transactions. The main domain is signin.spark.co.nz.

Submitted URL: https://www.spark.co.nz/cwa/openam/SSORedirect/metaAlias/Xtramail/idp1?SAMLRequest=hZLdbtswDIVfxdC9LTupO1dIAhhJCwTotiLphqE3haqwqDD9TaTrbk8%2FyWmH7Ka9EkDygOc74gKlNUH0Az25HfwaAKl4scahmBpLNkQnvESNwkkLKEiJff%2F5WsyqWoToyStv2InkfYVEhEjaO1ZsN0t2P7%2Bcn3d1f%2FGpaZtmftF1bbtZXzX9vD%2FrLtdtz4rvEDHNL1mSJxHiAFuHJB2lUj07L%2Bu2bM5uZ7VoO9E2d6zYJAbtJE2qJ6KAgvNxHCsMMv6slK%2FcH65GyX2A5JDv9193cNARFHELJHujJfIfFKWV2nB9CA0r1t4h5J3v0anjkFBDjOkttQ1GK02suPJRwRTykj1Kg5BRblIa%2Bhn%2BVfq3cPKywULcQ3zWCr7trk9A4CHbql6Sv1cWC8Z4x4NH2gGGbIKtFvkzxJRXXMkQcNAEZS6WNMYFP20vjkfwJQFtNzc%2Bef6dHVv5AW%2Bu6EP5OI2KZMihTtyJJBka1xEkJTqKAzC%2BOq78%2F9RWfwE%3D&RelayState=https%3A%2F%2Fwebmail.xtra.co.nz%2Findex.cgi&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=kjq3ixsAyQiuHuNTp7eoTo3YSAcb44HMrqvMOKFDAyZIlVMt5r0mxZNLaghhvJMLdgNdMd7XVGAGQjT8jfNmykIBnq2n%2BWK9y%2BSDjV%2Fnn6U%2F7qRVXue0djZHpetXD3PnvbmGMxzy9s7imoqV7woaspS95l2N77pe9UMYkEbHW6If517jqZM5osGVqaxeUBp9Qkwkt8d53N90CP7z4X5DmIHIT2TbQqkC6JEWEUKd4w6%2F9RemVi8cPMKqwEx7nrIJnNopQGqVipN%2F835rKpExbPtQ5%2BYxkDOl6F6ovGBqrrYuaVrNPbFMn5T0uUhjDFiclTkwuM6xhO9Y96SUsMDdLQ%3D%3D

Effective URL: https://signin.spark.co.nz/?goto=https://www.spark.co.nz/xtramail/checkcookies?spEntityID%3Dappsuite-saml-twr%26goto%3Dhttp://openam.internal.spark.co.nz:8080/openam/saml2/continue/metaAlias/Xtramail/idp1?secondVisitUrl%253D/SSORedirect/metaAlias/Xtramail/idp1?ReqID%25253D_3E3680A971511398855DCF1A3A48EC5A%26AMAuthCookie%3D&brand=xtramailRedirected

The Cisco Umbrella rank of the primary domain is #416,869 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 88%

10
Risk Score

The site presents a credential‑phishing login for Xtra Mail on a low‑ranked, newly‑registered Spark domain, reinforced by critical IDS alerts and heavily obfuscated JavaScript.

Risk Factors
Low domain ranking for a well‑known brand
Unknown domain age combined with credential form
Critical IDS alerts indicating possible data exfiltration and C2 activity
Highly obfuscated JavaScript code
Credential collection on a subdomain that does not match official Xtra Mail branding
Domain age information unavailable

Details

Page Title

Sign in

Scan Type

public

Language

🇺🇸

English

(54% confidence)

Category

healthcare medical

(29%)

Domain Information

Within the New Zealand country-code top-level domain (.co.nz), 'www.spark.co.nz' is registered and includes subdomain 'www'. The core label 'spark' covers 5 characters containing one vowel alongside four consonants. Breaking it apart gives one word: spark. The median word length lands at 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.spark.co.nz/cwa/openam/SSORedirect/metaAlias/Xtramail/idp1?SAMLRequest=hZLdbtswDIVfxdC9LTupO1dIAhhJCwTotiLphqE3haqwqDD9TaTrbk8%2FyWmH7Ka9EkDygOc74gKlNUH0Az25HfwaAKl4scahmBpLNkQnvESNwkkLKEiJff%2F5WsyqWoToyStv2InkfYVEhEjaO1ZsN0t2P7%2Bcn3d1f%2FGpaZtmftF1bbtZXzX9vD%2FrLtdtz4rvEDHNL1mSJxHiAFuHJB2lUj07L%2Bu2bM5uZ7VoO9E2d6zYJAbtJE2qJ6KAgvNxHCsMMv6slK%2FcH65GyX2A5JDv9193cNARFHELJHujJfIfFKWV2nB9CA0r1t4h5J3v0anjkFBDjOkttQ1GK02suPJRwRTykj1Kg5BRblIa%2Bhn%2BVfq3cPKywULcQ3zWCr7trk9A4CHbql6Sv1cWC8Z4x4NH2gGGbIKtFvkzxJRXXMkQcNAEZS6WNMYFP20vjkfwJQFtNzc%2Bef6dHVv5AW%2Bu6EP5OI2KZMihTtyJJBka1xEkJTqKAzC%2BOq78%2F9RWfwE%3D&RelayState=https%3A%2F%2Fwebmail.xtra.co.nz%2Findex.cgi&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=kjq3ixsAyQiuHuNTp7eoTo3YSAcb44HMrqvMOKFDAyZIlVMt5r0mxZNLaghhvJMLdgNdMd7XVGAGQjT8jfNmykIBnq2n%2BWK9y%2BSDjV%2Fnn6U%2F7qRVXue0djZHpetXD3PnvbmGMxzy9s7imoqV7woaspS95l2N77pe9UMYkEbHW6If517jqZM5osGVqaxeUBp9Qkwkt8d53N90CP7z4X5DmIHIT2TbQqkC6JEWEUKd4w6%2F9RemVi8cPMKqwEx7nrIJnNopQGqVipN%2F835rKpExbPtQ5%2BYxkDOl6F6ovGBqrrYuaVrNPbFMn5T0uUhjDFiclTkwuM6xhO9Y96SUsMDdLQ%3D%3D

Page Load Overview

5.79s
Total Load Time
20
HTTP Requests
3
Domains
164 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:54%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:54%
Script Type:Latin
Text Length:187 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical29% confidence
Type: spa
Method: ml+structural

All Detected Categories

healthcare medical
29%
technology software
27%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
866.22.91.48Auckland, Auckland, New Zealand
AS48851Radware Ltd
634.160.81.0Kansas City, Missouri, United States
AS396982Google LLC
666.22.91.1Auckland, Auckland, New Zealand
AS48851Radware Ltd
203--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18863B7DA1530A28815CEE54FDF6FEEC8105B605BE8A2D5C1BAED8B0C5B8BED4FD41844

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:ue/VIzxEU+g47r7qa1ZI42rZR0HI2GDolf:uol0rNg

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:70621:MCABcBSUnjFgAYEkcJtAa0rDQoU45GBwEMQAUhMAwFEgGGGAIIoRCpSKswQBCiRgYQCT6iYArECBEuIgIDUDAIATSeA0wVKQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1018181818180000
Perceptual Hash:8dc877227626dc27
Difference Hash:b2b2b2b2b3b34326
Wavelet Hash:18181819191b83c7
Color Hash:#7be06c

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data