Security Scan Report: ndxx1-bento123.com

Site favicon
Submitted: Jan 3, 2026, 9:00:48 PMCompleted: Jan 3, 2026, 9:02:38 PMpubliccompleted
Loading additional data...

Summary

This website contacted 8 IPs in 3 countries across 6 domains to perform 299 HTTP transactions. The main domain is ndxx1-bento123.com and was registered NaN years ago.

Submitted URL: https://ndxx1-bento123.com/desktop/game/livecasino/pragmaticplay

AI Security Verdict

High Risk

Confidence: 88%

9
Risk Score

Site is high‑risk due to hidden password field and very new unranked domain; likely phishing.

Risk Factors
Hidden password field (credential harvesting)
Login form on a brand‑new (10‑day) domain
Very new, unranked domain
Domain age information unavailable

Details

Page Title

BENTO123 # Situs Slot Online Dengan Bonus Promosi Paling Menguntungkan 2025.

Scan Type

public

Language

🇮🇩

ID

(80% confidence)

Category

gambling betting

(83%)

Domain Information

Domain 'ndxx1-bento123.com' uses the commercial generic top-level domain (.com) while skipping any subdomain. Its registrable label 'ndxx1-bento123' stretches across 14 characters split between two vowels and seven consonants, notching four digits and one hyphen. It segments into five words: nd, xx, 1, bento, 123. Median word length comes out to two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ndxx1-bento123.com/desktop/game/livecasino/pragmaticplay

Page Load Overview

33.08s
Total Load Time
228
HTTP Requests
6
Domains
348 KB
Total Size

Language Analysis

Primary Language

🇮🇩Indonesian
Code: id
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

Language Code:id
Detection Confidence:80%
Script Type:Unknown
HTML Lang Attribute:id
Text Length:2,961 chars
Detector Agreement:80%

Website Classification

Primary Category

gambling betting83% confidence
Type: webapp
Method: ml+structural

All Detected Categories

gambling betting
83%
entertainment media
72%
social media network
64%
technology software
48%
cryptocurrency blockchain
47%

Detected Features

Login Form
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3223.50.131.150Netherlands
2845.192.223.64Mauritius
AS13335CLOUDFLARENET
2823.50.131.153United States
2895.100.110.19MauritiusUnknown
2865.8.102.99UnknownUnknown
2823.36.162.25UnknownUnknown
2823.36.162.17UnknownUnknown
2865.8.102.94UnknownUnknown
2288--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E5D3EB2358E13022127394E57DA47E0AEEC5A203C21A8E44F1FD47B95FE7F569C137AA

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:x9CZdOTXOYBtZ+gDTBCs1cVQf/NYvpULCsagvVkngJxIebX0/SBVx/sauh3Z:LCZdOTXOYBtZbDTBUQfupetjDx/sauhp

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:139402:WFNAJYDglgioYBCcNhExRwEUmEABsIQBKQAAaQonIgJsSEDIREHJagxkMH2C0FXBFWAUSzgAMLDioEoAwS0XcgFgMEgiIsED

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:20183f3c3c3c3919
Perceptual Hash:8ad42177768ed989
Difference Hash:4df3f1616979716b
Wavelet Hash:20183f3d3c3c3d3d
Color Hash:#6c8de0

Scan History

Scan history not available

Unable to load historical scan data