Security Scan Report: ndxx1-bento123.com

Site favicon
Submitted: Dec 27, 2025, 4:10:19 PMCompleted: Dec 27, 2025, 4:10:53 PMpubliccompleted
Loading additional data...

Summary

This website contacted 6 IPs in 2 countries across 6 domains to perform 506 HTTP transactions. The main domain is ndxx1-bento123.com and was registered NaN years ago.

Submitted URL: https://ndxx1-bento123.com/desktop/game/livecasino/dreamgaming

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed phishing scam; credential harvesting on a newly registered, untrusted domain.

Risk Factors
Brand new domain (<7 days) collecting credentials
Disguised password fields
Hidden password fields
Unranked domain with no reputation
Multiple password fields on a gambling‑style site
Domain age information unavailable

Details

Page Title

BENTO123 # Situs Slot Online Dengan Bonus Promosi Paling Menguntungkan 2025.

Scan Type

public

Language

🇮🇩

ID

(80% confidence)

Category

gambling betting

(94%)

Domain Information

Domain 'ndxx1-bento123.com' uses the commercial generic top-level domain (.com). The registrable portion 'ndxx1-bento123' spans 14 characters split between two vowels and 7 consonants, notching 4 digits and 1 hyphen. Splitting it apart reveals 5 words: nd, xx, 1, bento, 123. Median word length is two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ndxx1-bento123.com/desktop/game/livecasino/dreamgaming

Page Load Overview

13.06s
Total Load Time
486
HTTP Requests
7
Domains
2.7 MB
Total Size

Language Analysis

Primary Language

🇮🇩Indonesian
Code: id
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

Language Code:id
Detection Confidence:80%
Script Type:Unknown
HTML Lang Attribute:id
Text Length:5,849 chars
Detector Agreement:80%

Website Classification

Primary Category

gambling betting94% confidence
Type: webapp
Method: ml+structural

All Detected Categories

gambling betting
94%
entertainment media
83%
documentation technical
73%
technology software
58%
adult content
38%

Detected Features

Login Form
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8145.192.223.64Mauritius
AS13335CLOUDFLARENET
8123.50.131.153Germany
8123.36.162.17Mauritius
8123.50.131.150UnknownUnknown
8123.36.162.25UnknownUnknown
8165.8.102.94UnknownUnknown
4866--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T123340A125842343B3637B2987CF57B4495B10287C2278F0872FC4696BFE6E696913EDE

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:lCOOYBtZbDTiJYMuDXtsHqWNigO9AUr9AU2+o5:lGJYDWrZJ5

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:250086:gqHYBIKSAiLjjBqAAJ4YIVYKwkCADACBaAAoEiK4mLpQSAiCJMYaAYC4gAB2ZntRovlkR0ifVFRJkUkdJZQH5gs8AME0NUIO

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:2c103f3c3c3c3d19
Perceptual Hash:8ad52373768a99a9
Difference Hash:49f3f1616971716b
Wavelet Hash:2c183f3d3c3c3d19
Color Hash:#53ac5f

Scan History

Scan history not available

Unable to load historical scan data