Security Scan Report: bento123ndxhealth.xyz

Site favicon
Submitted: Dec 30, 2025, 12:58:00 AMCompleted: Dec 30, 2025, 12:59:24 AMpubliccompleted
Loading additional data...

Summary

This website contacted 9 IPs in 2 countries across 7 domains to perform 505 HTTP transactions. The main domain is bento123ndxhealth.xyz and was registered NaN years ago.

Submitted URL: https://bento123ndxhealth.xyz/desktop/game/slot/clotplay

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed phishing site harvesting credentials; avoid and report.

Risk Factors
Brand‑new domain (<7 days) with login form
Disguised password fields (type='text' with password placeholder)
Hidden password fields
Unicode evasion in form inputs
Multiple password fields without clear purpose
Domain age information unavailable

Details

Page Title

BENTO123 # Situs Slot Online Dengan Bonus Promosi Paling Menguntungkan 2025.

Scan Type

public

Language

🇮🇩

ID

(80% confidence)

Category

gambling betting

(94%)

Domain Information

You're looking at domain 'bento123ndxhealth.xyz' on the open generic top-level domain (.xyz) without a subdomain. The registrable portion 'bento123ndxhealth' spans 17 characters containing 4 vowels alongside ten consonants, along with three digits. It segments into 5 words: bento, 123, nd, x, health. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bento123ndxhealth.xyz/desktop/game/slot/clotplay

Page Load Overview

13.76s
Total Load Time
501
HTTP Requests
8
Domains
3.2 MB
Total Size

Language Analysis

Primary Language

🇮🇩Indonesian
Code: id
Confidence:80%
Script:Unknown
Direction:ltr

Detection Details

Language Code:id
Detection Confidence:80%
Script Type:Unknown
HTML Lang Attribute:id
Text Length:7,241 chars
Detector Agreement:80%

Website Classification

Primary Category

gambling betting94% confidence
Type: webapp
Method: ml+structural

All Detected Categories

gambling betting
94%
entertainment media
83%
documentation technical
73%
technology software
58%
adult content
38%

Detected Features

Login Form
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6152.222.232.184United States
AS16509AMAZON-02
5565.8.102.45United States
AS16509AMAZON-02
5523.50.131.150Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
55188.114.96.3United States
AS13335CLOUDFLARENET
5523.36.162.17GermanyUnknown
5552.222.232.119United States
AS16509AMAZON-02
5523.50.131.153Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
5565.8.102.72GermanyUnknown
55188.114.97.3United States
AS13335CLOUDFLARENET
5019--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12864082155D634373137B1D87CA53B459EB19287C12B8F0872FC4BA27FE2D68AC13A99

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:lCOOYBtZbDTiJYshQYrtaTPkwx6mbAG9AUk9AUTuZVb:lGJYYtqswx6mbA587Vb

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:327138:KTQi0AOAiCKCCKIAZhWoQEDGJlIcrIJACUYi8AWgBpQYtAUgUCNo4JchknAKCgKEsKhwzQMS0RJoRapHAkACJBBEAcwieomC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:2c10fd3d183c3d3d
Perceptual Hash:8a742353378bd3b8
Difference Hash:49b4f17171617969
Wavelet Hash:2c107d3d383c3d3d
Color Hash:#ab53ac

Scan History

Scan history not available

Unable to load historical scan data