Security Scan Report: ndxx-bento123.com

Site favicon
Submitted: Dec 31, 2025, 3:00:35 AMCompleted: Dec 31, 2025, 3:02:58 AMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 3 countries across 7 domains to perform 337 HTTP transactions. The main domain is ndxx-bento123.com and was registered NaN years ago.

Submitted URL: https://ndxx-bento123.com/desktop/game/slot/cq9

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed phishing site harvesting credentials on a newly registered, unranked domain.

Risk Factors
Brand‑new domain (<7 days) with login form
Hidden password field (type="password" but not visible)
Unranked/low‑reputation domain impersonating a gambling brand
Domain age information unavailable

Details

Page Title

BENTO123 # Situs Slot Online Dengan Bonus Promosi Paling Menguntungkan 2025.

Scan Type

public

Language

🇮🇩

ID

(80% confidence)

Category

entertainment media

(89%)

Domain Information

The domain name 'ndxx-bento123.com' uses the commercial generic top-level domain (.com) while skipping any subdomain. The registrable portion 'ndxx-bento123' spans 13 characters containing 2 vowels alongside seven consonants, notching 3 digits and 1 hyphen. Tokenizing the label suggests four words: nd, xx, bento, 123. Average segment length settles at 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ndxx-bento123.com/desktop/game/slot/cq9

Page Load Overview

63.05s
Total Load Time
235
HTTP Requests
7
Domains
707 KB
Total Size

Language Analysis

Primary Language

🇮🇩Indonesian
Code: id
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

Language Code:id
Detection Confidence:80%
Script Type:Unknown
HTML Lang Attribute:id
Text Length:4,895 chars
Detector Agreement:80%

Website Classification

Primary Category

entertainment media89% confidence
Type: webapp
Method: ml+structural

All Detected Categories

entertainment media
89%
gambling betting
63%
adult content
53%
finance banking
35%
e-commerce shopping
35%

Detected Features

Login Form
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3745.192.223.64Mauritius
AS13335CLOUDFLARENET
3313.226.247.213Mauritius
3365.8.102.94United States
AS16509AMAZON-02
3323.50.131.153UnknownUnknown
3365.8.102.72UnknownUnknown
3395.100.110.26UnknownUnknown
3323.36.162.25Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
2357--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11344BC3114F1243211B380E579A4AA4BAFD1F603D61B8F84B1FD6BE15FD7E96AC13229

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:8CdOOYBtZbDThQfup5s1LdX3x7Q6kx/sauhp:8CdOOYBtZbDThQfup5s1LdX3xcBa

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:261769:Ow1CeMIVBFQUbECoFQQJAAwQahLItAQoWAtgIiRXmgKESADgCLSaAHIwGAgkuC6icEch0sA1Y3YagKFEKwipKBgABEsIFhAa

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:2010fd3d003c3d3d
Perceptual Hash:8a742277368fd338
Difference Hash:4db0f171f1696969
Wavelet Hash:2038ff3f003c3d3d
Color Hash:#6ccee0

Scan History

Scan history not available

Unable to load historical scan data