Security Scan Report: ndxx1-bento123.com

Site favicon
Submitted: Dec 31, 2025, 9:52:22 PMCompleted: Dec 31, 2025, 9:53:39 PMpubliccompleted
Loading additional data...

Summary

This website contacted 10 IPs in 3 countries across 7 domains to perform 321 HTTP transactions. The main domain is ndxx1-bento123.com and was registered NaN years ago.

Submitted URL: https://ndxx1-bento123.com/desktop/game/slot/pragmaticplay

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed phishing scam: hidden password field on a brand‑new, unranked gambling site.

Risk Factors
Brand‑new domain (<7 days) with credential collection
Hidden password field in HTML
Presence of a login form on a newly registered, low‑reputation site
Unranked domain lacking any established reputation
Gambling‑related content on a suspicious domain
Domain age information unavailable

Details

Page Title

BENTO123 # Situs Slot Online Dengan Bonus Promosi Paling Menguntungkan 2025.

Scan Type

public

Language

🇮🇩

ID

(80% confidence)

Category

entertainment media

(83%)

Domain Information

Domain 'ndxx1-bento123.com' uses the commercial generic top-level domain (.com) without a subdomain. The core label 'ndxx1-bento123' covers 14 characters containing 2 vowels alongside seven consonants, along with four digits and 1 hyphen. Breaking it apart gives 5 words: nd, xx, 1, bento, 123. The median word length lands at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ndxx1-bento123.com/desktop/game/slot/pragmaticplay

Page Load Overview

8.80s
Total Load Time
255
HTTP Requests
7
Domains
993 KB
Total Size

Language Analysis

Primary Language

🇮🇩Indonesian
Code: id
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

Language Code:id
Detection Confidence:80%
Script Type:Unknown
HTML Lang Attribute:id
Text Length:14,182 chars
Detector Agreement:60%

Website Classification

Primary Category

entertainment media83% confidence
Type: webapp
Method: ml+structural

All Detected Categories

entertainment media
83%
gambling betting
81%
adult content
35%
technology software
34%
social_media
25%

Detected Features

Login Form
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3065.8.102.94United States
AS16509AMAZON-02
2523.50.131.153Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
2513.226.247.206United States
AS16509AMAZON-02
2523.36.162.17UnknownUnknown
252.21.239.210Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
2545.192.223.64Mauritius
AS13335CLOUDFLARENET
2595.100.110.26Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
2565.8.102.45UnknownUnknown
2513.226.247.189United States
AS16509AMAZON-02
252.21.239.206Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
25510--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1FA05983010F6642315A380E47964AF8B6F81F617D65B8BC4B2BD6BE25FD3D95EC23224

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:LCZOOYBtZbDTsQHshboT1CMKACbWGCFmxCAZa:LCUshbba

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:827616:qZZKaoBIQA7QEu4lHVEABkIEidQDAUAQEUiAiChUFAdRFIqzDM22GrKABiLRhihGD0ssRoPIDHMMhVAikYBY8C+YSBiiAA3g

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:2010fd3d003c3d3d
Perceptual Hash:8a742377278bd338
Difference Hash:4db0f171f1696969
Wavelet Hash:2038ff3f003c3d3d
Color Hash:#1f4c93

Scan History

Scan history not available

Unable to load historical scan data