moonpay-commerce-3bex710ga-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-3bex710ga-heliofi.vercel.app
This website appears to present itself as a cryptocurrency payments and checkout service under the name "MoonPay Commerce." Based on the page title, metadata, and visible interface, it is designed to collect an email address or prompt a wallet-based sign-in for users interested in crypto payment links, checkout widgets, subscriptions, and related commerce features.
The domain itself is hosted on a vercel.app subdomain rather than on an apparent primary corporate domain. The page references commerce.moonpay.com and uses branding associated with MoonPay, which suggests it may be attempting to resemble or replicate a financial-services landing page connected to a crypto payments provider.
From the visible content, this is not a broad informational website but a focused landing page for account access or onboarding. Its category is most consistent with financial services, specifically cryptocurrency payments, although the hosting pattern and scan results warrant caution when interpreting its legitimacy.
Safety Assessment for moonpay-commerce-3bex710ga-heliofi.vercel.app
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 15 out of 91 security engines, with many classifying it as phishing or fraud-related. In addition, several web-classification sources categorized it as phishing or financial fraud, even though some blacklist databases focused on malware and phishing URLs did not report a listing at the time of review.
The page also uses branding that appears to imitate a known crypto-payment service while operating from a third-party hosting subdomain rather than an apparent official primary domain. That combination can be consistent with look-alike login or credential-harvesting pages. A malware scan did not detect malicious files on the page itself, but absence of file-based malware does not rule out phishing behavior. The domain's IP address was also listed on one mail-reputation blocklist, which is a weaker signal than phishing detections but still adds some caution.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by a mainstream certificate authority, with expiry shown in late 2026. It is hosted on Vercel infrastructure, with nameservers pointing to Vercel DNS and the web server identified as Vercel. The page appears to be built with a modern JavaScript framework, with numerous _next/static assets indicating a Next.js deployment.
DNSSEC appears to be unsigned, which is common but means DNS responses do not benefit from DNSSEC validation. No malicious files were detected in the file scan, and no flagged iframes were reported, but one referenced external domain was marked by a heuristic scanner. The more significant technical concern is not the TLS setup but the combination of phishing detections, brand-style presentation, and deployment on a hosted subdomain rather than an apparent official corporate domain.
Share your experience with this website. Was it safe? Did you encounter any issues?