Security Scan Report: ndxx1-bento123.com

Site favicon
Submitted: Dec 29, 2025, 2:17:42 PMCompleted: Dec 29, 2025, 2:19:45 PMpubliccompleted
Loading additional data...

Summary

This website contacted 6 IPs in 3 countries across 7 domains to perform 508 HTTP transactions. The main domain is ndxx1-bento123.com and was registered NaN years ago.

Submitted URL: https://ndxx1-bento123.com/desktop/game/slot/habanero

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Confirmed phishing scam; new domain harvesting credentials via deceptive form fields.

Risk Factors
Brand new domain (<7 days) with credential collection form
Disguised password fields (type='text' with password placeholder)
Hidden password fields in the page source
Multiple password fields increasing credential harvesting potential
Unicode evasion used to obscure field names
Domain age information unavailable

Details

Page Title

BENTO123 # Situs Slot Online Dengan Bonus Promosi Paling Menguntungkan 2025.

Scan Type

public

Language

🇮🇩

ID

(80% confidence)

Category

gambling betting

(94%)

Domain Information

Domain 'ndxx1-bento123.com' uses the commercial generic top-level domain (.com) with no subdomain. The core label 'ndxx1-bento123' covers 14 characters containing 2 vowels alongside 7 consonants, plus four digits and one hyphen. It segments into 5 words: nd, xx, 1, bento, 123. Median word length comes out to two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ndxx1-bento123.com/desktop/game/slot/habanero

Page Load Overview

54.59s
Total Load Time
504
HTTP Requests
8
Domains
3.1 MB
Total Size

Language Analysis

Primary Language

🇮🇩Indonesian
Code: id
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

Language Code:id
Detection Confidence:80%
Script Type:Unknown
HTML Lang Attribute:id
Text Length:9,279 chars
Detector Agreement:60%

Website Classification

Primary Category

gambling betting94% confidence
Type: webapp
Method: ml+structural

All Detected Categories

gambling betting
94%
entertainment media
83%
documentation technical
73%
technology software
58%
adult content
38%

Detected Features

Login Form
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8423.36.162.25Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
8452.222.232.184United States
AS16509AMAZON-02
8423.36.162.17Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
8445.192.223.64Mauritius
AS13335CLOUDFLARENET
8423.50.131.153Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
8465.8.102.99UnknownUnknown
5046--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C5A4C63116E62537357370D43C602A8AAEB1A24BC5678F4473FC5BA23FE3D98AC13659

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:lCOOYBtZbDTiJYdqG1vtO9AU39AU54ZVZ5:lGJYg8v7FlVZ5

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:451437:iEAEq1kmBhiJAQBDNZGa4wwgSAAAgiM0YE+NjATSA4ARkjopUABLSwBkQlFHQEkWAhByEY4KCBRDiF6XTAAg0gICgsACJZse

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:2c10fd3d183c3d3d
Perceptual Hash:8a742357278bd339
Difference Hash:49b4f17171696969
Wavelet Hash:2c107d3d383c3d3d
Color Hash:#9e87c5

Scan History

Scan history not available

Unable to load historical scan data