Security Scan Report: ndxx1-bento123.com

Site favicon
Submitted: Dec 26, 2025, 2:54:36 PMCompleted: Dec 26, 2025, 2:55:14 PMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 4 countries across 7 domains to perform 594 HTTP transactions. The main domain is ndxx1-bento123.com and was registered NaN years ago.

Submitted URL: https://ndxx1-bento123.com/

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Confirmed scam: new domain with hidden/disguised password fields used for credential harvesting.

Risk Factors
Brand‑new domain (<7 days) hosting a credential‑harvesting form
Disguised password fields (type='text' with password placeholder)
Multiple password fields increase credential collection potential
Unicode evasion technique to obscure field names
Domain age information unavailable

Details

Page Title

BENTO123 # Situs Slot Online Dengan Bonus Promosi Paling Menguntungkan 2025.

Scan Type

public

Language

🇮🇩

ID

(80% confidence)

Category

gambling betting

(94%)

Domain Information

You're looking at domain 'ndxx1-bento123.com' on the commercial generic top-level domain (.com). Count 14 characters in 'ndxx1-bento123' split between 2 vowels and 7 consonants; it also includes four digits and one hyphen. Segmentation suggests five words: nd, xx, 1, bento, 123. Median word length comes out to 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ndxx1-bento123.com/

Page Load Overview

9.81s
Total Load Time
538
HTTP Requests
8
Domains
6.7 MB
Total Size

Language Analysis

Primary Language

🇮🇩Indonesian
Code: id
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

Language Code:id
Detection Confidence:80%
Script Type:Unknown
HTML Lang Attribute:id
Text Length:6,556 chars
Detector Agreement:80%

Website Classification

Primary Category

gambling betting94% confidence
Type: webapp
Method: ml+structural

All Detected Categories

gambling betting
94%
entertainment media
83%
documentation technical
73%
technology software
58%
adult content
38%

Detected Features

Login Form
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
822.21.239.206United States
7695.100.110.19Mauritius
7623.36.162.25Norway
7623.50.131.150NetherlandsUnknown
7665.8.102.94UnknownUnknown
7645.192.223.64Mauritius
AS13335CLOUDFLARENET
7652.222.232.141UnknownUnknown
5387--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T150642A21589234373137B1D87DB56B44A6F14247C2178F08B2FC86966FE6E68AD03F9E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:lCOOYBtZbDTiJYkL7vWVnYxQD3aSL9AUj9AU5QmVc5y:lGJYkPvAZ3adFU65y

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:313790:wuREFAKBDqQuAEYBIJRQEZ0i0kIBUIWaIEAFlgAhEQsEQhDBDgSqq3FBBVjT5cwIagAQDAEND5SMiCgEIJ1ITQCBAgApoRIw

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0030fcfe3cfc0101
Perceptual Hash:db5522331d34d393
Difference Hash:48e1f03278eacf6b
Wavelet Hash:0038fcff3efd0121
Color Hash:#2dd274

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data