Security Scan Report: ndxx1-bento123.com

Site favicon
Submitted: Jan 5, 2026, 1:31:10 AMCompleted: Jan 5, 2026, 1:33:08 AMpubliccompleted
Loading additional data...

Summary

This website contacted 9 IPs in 3 countries across 7 domains to perform 335 HTTP transactions. The main domain is ndxx1-bento123.com and was registered NaN years ago.

Submitted URL: https://ndxx1-bento123.com/desktop/game/slot/cq9

AI Security Verdict

High Risk

Confidence: 92%

10
Risk Score

High‑risk phishing site with hidden password field on a newly registered domain.

Risk Factors
Hidden password field (credential harvesting)
Login form on a very new (11‑day) domain
Unranked domain with no reputation
Domain age < 30 days increases phishing likelihood
Domain age information unavailable

Details

Page Title

BENTO123 # Situs Slot Online Dengan Bonus Promosi Paling Menguntungkan 2025.

Scan Type

public

Language

🇮🇩

ID

(80% confidence)

Category

entertainment media

(88%)

Domain Information

Domain 'ndxx1-bento123.com' uses the commercial generic top-level domain (.com) while skipping any subdomain. Its registrable label 'ndxx1-bento123' stretches across 14 characters with two vowels and seven consonants, plus four digits and 1 hyphen. Breaking it apart gives five words: nd, xx, 1, bento, 123. Expect 2 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ndxx1-bento123.com/desktop/game/slot/cq9

Page Load Overview

38.23s
Total Load Time
234
HTTP Requests
8
Domains
740 KB
Total Size

Language Analysis

Primary Language

🇮🇩Indonesian
Code: id
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

Language Code:id
Detection Confidence:80%
Script Type:Unknown
HTML Lang Attribute:id
Text Length:4,934 chars
Detector Agreement:60%

Website Classification

Primary Category

entertainment media88% confidence
Type: webapp
Method: ml+structural

All Detected Categories

entertainment media
88%
gambling betting
67%
adult content
53%
finance banking
39%
e-commerce shopping
34%

Detected Features

Login Form
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2613.226.247.206Mauritius
2665.8.102.99Germany
2613.226.247.189United States
2645.192.223.64Mauritius
AS13335CLOUDFLARENET
2623.36.162.25UnknownUnknown
2665.8.102.94UnknownUnknown
2623.50.131.153UnknownUnknown
2623.50.131.150UnknownUnknown
2623.36.162.17UnknownUnknown
2349--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18944BD3114F2242311B380E579A4AA4BAFD1F603D61B8F84B1FD6BE15FD7E96AC13225

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:LCZdOTXOYBtZbDTB7Qfgpis1LdX3xWj1dx/sauhp:LCZdOTXOYBtZbDTB7Qfgpis1LdX3x8la

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:260997:gEABagRgoBQQMSLg0TFJRF0tZgAwgOSNhAk0KQBS9PMFRAOmgYU6EGXrEQi4kCkGlA9L4AALAwGBABgAwEAtAOJAZbCpEuHb

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:2010fd3d003c3d3d
Perceptual Hash:8a742277368fd338
Difference Hash:4db0f171f1696969
Wavelet Hash:2038ff3f003c3d3d
Color Hash:#a379d2

Scan History

Scan history not available

Unable to load historical scan data