Security Scan Report: switchfirm.org

Site favicon
Submitted: Dec 3, 2025, 9:45:32 PMCompleted: Dec 3, 2025, 9:47:19 PMpubliccompleted
Loading additional data...

Summary

This website contacted 16 IPs in 2 countries across 6 domains to perform 19 HTTP transactions. The main domain is switchfirm.org and was registered NaN years ago.

Submitted URL: https://switchfirm.org/

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Impersonates Nintendo brand on a new, unranked domain; classified as confirmed phishing scam.

Risk Factors
Brand impersonation of Nintendo on an unrelated domain
Newly registered domain (<90 days) with no reputation
Unranked domain (not in top 1M) increasing suspicion
Domain age information unavailable

Details

Page Title

Nintendo Switch Firmware Downloads - Switchfirm

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(49%)

Domain Information

The domain 'switchfirm.org' uses the non-profit oriented generic top-level domain (.org) with no subdomain. The core label 'switchfirm' covers 10 characters split between 2 vowels and eight consonants. Tokenizing the label suggests 2 words: switch, firm. Median word length comes out to 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://switchfirm.org/

Page Load Overview

0.60s
Total Load Time
19
HTTP Requests
6
Domains
3.8 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:5,150 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software49% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
49%
entertainment media
46%
documentation technical
44%
corporate
25%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
881.169.145.151Germany
AS6724Strato GmbH
4172.217.18.3United States
AS15169GOOGLE
3216.239.34.36United States
AS15169GOOGLE
2216.58.206.72United States
AS15169GOOGLE
1142.250.184.202United States
AS15169GOOGLE
1216.239.32.36United States
AS15169GOOGLE
1104.20.38.66United States
AS13335CLOUDFLARENET
12001:4860:4802:34::36United States
AS15169GOOGLE
12a00:1450:4001:831::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
12a01:238:20a:202:1151::Germany
AS6724Strato GmbH
1916--

Detected Technologies1

40%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T171E21F31E1E01AFEA20255D8999DE30CFDA2E207D08D8594B07DD2EDDBDEDB2A55B007

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:EwaIVFLb57V5Zrrh3dR5TRXX5l7l5r6/F3fNZ1rM6PRfHjiq:ELIVFLb57V5Zrrh3dR5TRXX5l7l5r6/l

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:32903:GIIkYEAxKcGkMqQhCoQBAjIMBUBzguFRMAUUgEANsFQoDgWMMBhgEDg4JoUg0MzGIAoAQUjhUjAGDMASQtCKQS3CSgQABwRk

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:f12503fce4039fe4
Perceptual Hash:ea6d6d8cc28c28af
Difference Hash:674947c44c37394d
Wavelet Hash:f12501fee4039fe4
Color Hash:#b96ce0

Other Hashes

Crop Resistant:674947c44c37394d

Scan History

Scan history not available

Unable to load historical scan data