Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 16. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

justica-rcbe[.]com

“rcbe.justica.gov.pt/”

Threat verdict Critical 95/100 evidence score
Availability Server error The latest stored response was inconclusive
VirusTotal detections: 16/91 Spamhaus DBL: DBL_BOTNET Young domain: 28 days old
Jul 16, 2026

Evidence Summary

CRITICAL
Evidence score
95/100

This domain, justica-rcbe.com, was registered on 15 July 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently active. DNS resolution points to the IPv4 address 64.89.160.3, and authoritative name servers are ns1.erans.ru and ns2.erans.ru. The domain is classified as a generic phishing site and has been assigned a high risk rating. VirusTotal reports a single detection out of 91 scanned security engines, indicating that at least one vendor identified malicious behavior. No public content analysis or payload samples have been published, so the exact phishing technique, targeted brands, and victim profile remain unknown. The short age of the domain, combined with its active status, suggests a likely ongoing campaign. Defenders should immediately block justica-rcbe.com at DNS and proxy layers, add the associated IP address 64.89.160.3 to network‑level deny lists, and monitor for any outbound connections to the erans.ru name servers. Continuous re‑scanning on VirusTotal and other sandbox services is advised to capture any evolving indicators. Logging of DNS queries for this domain can provide early warning of infection attempts.

VirusTotal
VirusTotal
16 det.
TLS Certificate
Let's Encrypt / YR1
Age
28d Very New!
Observed status
Server error HTTP 502
PhishDestroy
DestroyList
Listed

Data Coverage

VirusTotal 16 / 91 URLQuery not checked PhishStats not checked OTX no community references CF Radar no data URLScan capture stored report URLScan verdict Analysis completed DNS blocks not checked TLS valid certificate, 61d WHOIS 28d old Screenshot 2 captures · 2 sources Redirect chain not probed
Network Security IntelligenceRegistrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

Threat Response Pipeline

Discovery
Checks
Reports
Availability
9/11

Blocklist coverage

10 monitored external feeds · stored snapshot Aug 12, 2026

10 monitored external feeds No match

Stored outcome evidence

Outcome & takedown attribution

Outcome
held
Availability
unreachable
Cause
registrar_client_hold
Actor
NICENIC INTERNATIONAL GROUP CO., LIMITED
Mechanism
client_hold
Confidence
95%
First observation
Latest observation

Estimated unavailability

Time to unavailability: 0 h

Evidence SHA-256 d2a96b95f599

Detection timeline

  1. Availability

    First stored value: DNS inactive

    f93a11f87e4d
  2. Availability

    DNS inactive → Unknown

    616489bff05e
  3. Domain status

    Reachable → Unreachable

  4. Availability

    Unknown → DNS inactive

    20e202f19385
  5. Availability

    DNS inactive → Held

    8fc3bbbc045b
  6. Availability

    Held → DNS inactive

    f52d526b76a1
  7. Availability

    DNS inactive → Unknown

    294c5e11403c
  8. Availability

    Unknown → Held

    bfcff3a04dcb
  9. Availability

    Held → Unknown

    51cea33e2683
  10. Availability

    Unknown → DNS inactive

    6dfe9145995c
Show all (13)
  1. Availability

    DNS inactive → Held

    6c3b5a7bdfad
  2. Availability

    Held → DNS inactive

    641ed81dc4d5
  3. Availability

    DNS inactive → Unknown

    55f0de5b9cff
  4. Availability

    Unknown → Held

    9e6b9edc1c76
  5. Availability

    Held → Unknown

    463287fd1cd9
  6. Availability

    Unknown → DNS inactive

    d0b7046e8c2f
  7. Availability

    DNS inactive → Held

    ea29ebc92cac
  8. Availability

    Held → DNS inactive

    ca9ed662b468
  9. Availability

    DNS inactive → Unknown

    46ab10666cc1
  10. Availability

    Unknown → Held

    84518b0ca2b5
  11. Availability

    Held → DNS inactive

    92f667ff6e00
  12. Availability

    DNS inactive → Unknown

    dd376798160a
  13. Availability

    Unknown → Held

    d2a96b95f599

Community reports

Reported by 0 community members, first seen Jul 16, 2026

Unique reported URLs
1

Community intelligence

1 community report

CategoryPHISHING

The PhishFort Detection System has flagged this as a domain threat, classified as null. Threat detected at 2026-07-16T21:04:35.356Z.

Stored Capture

Page Title
rcbe.justica.gov.pt/
TLS Certificate
Valid transport encryption · Issued by Let's Encrypt / YR1 · valid for 61 days

Domain Intelligence

Domain
URLScan Verdict Analysis completed score 0 report ↗
Server / ASN nginx · AS205759 Ghosty Networks LLC
IP Reputation IP abuse confidence 12/100 2 reports checked Jul 17, 2026
IP Address 64.89.160.3 LU
GeoLU Schieren, LU
NetworkAS205759 · Ghosty Networks LLC
RegistrationCreated Jul 15, 2026 (28d · Very New!) Expires Jul 15, 2027
HTTP Status502 Error
Elapsed Since First Report 20 days
What we count Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Server error.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
Technical detailsDNS, TLS names and timestamps
First DetectedJul 16, 2026
DOM Analysisanalyzed Jul 17, 2026DOM analysis score 93/100
Submitted URLhttp://justica-rcbe.com/
Nameserversns1.erans.runs2.erans.ru
MX Records10 mail.justica-rcbe.com
TLS fingerprint
TLS observationvalid from Jul 15, 2026scanned Jul 17, 2026
ICANN OVERSIGHT

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

16 / 91 security vendors flagged this domain
View on VT
Last analyzed Previous stored snapshot: 1 detection
alphaMountain.ai
BitDefender
Cluster25
CRDF
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Kaspersky
Lionic
PhishFort
SOCRadar
Sophos
VIPRE

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing

External tools

HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/justica-rcbe.com"
  title="PhishDestroy threat report for justica-rcbe.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

A Very Sincere Thank-You Note

Satirical draft generator

Recipient
Fee context

Satirical draft. Fee figures are estimates; exact attribution to this domain is not claimed.