moonpay-commerce-57n1p29nc-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-57n1p29nc-heliofi.vercel.app
This domain appears to present itself as a MoonPay Commerce login or onboarding page related to cryptocurrency payments. The page title and visible branding reference "MoonPay Commerce," and the content suggests a service for accepting crypto payments through pay links, checkout widgets, subscriptions, and merchant deposits. The interface shown in the screenshot is minimal and asks visitors to enter an email address or sign in with a wallet.
Based on the domain structure, this is not hosted on MoonPay's primary corporate domain but on a Vercel subdomain that includes the string "heliofi." The page also references assets from hel.io and includes links to commerce.moonpay.com, which may indicate an attempt to mimic or proxy branding associated with crypto payment services. Because the site uses recognizable commercial branding on a third-party hosting subdomain, it may be intended to resemble an official service portal rather than a standalone branded website.
Safety Assessment for moonpay-commerce-57n1p29nc-heliofi.vercel.app
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 14 out of 91 security engines, with many of those detections classifying it as phishing or otherwise malicious. The page also closely imitates MoonPay branding while operating from a vercel.app subdomain rather than an obvious official MoonPay domain, which may indicate a look-alike login page designed to collect credentials or wallet access.
Blacklist and threat-database results were mixed. Major content-focused threat databases included in the scan did not report listings at the time of this check, but the domain's IP address was listed on one mail-reputation blocklist. That type of listing is a weaker signal than direct phishing or malware listings, but it still adds some caution. The malware scan itself did not detect flagged files on the page, although one referenced domain was associated with a generic suspicious heuristic, which is lower-confidence on its own.
Taken together, the strongest indicators here are the multi-engine phishing detections, the use of recognizable financial/crypto branding on a third-party hosted subdomain, and the credential-collection style landing page. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by Google Trust Services, with expiry shown as 2026-09-26. It is hosted on Vercel infrastructure and resolves to IP address 64.29.17.3 in Walnut, United States. The page appears to be built with a modern JavaScript framework, with multiple _next/static assets indicating a Next.js deployment.
DNSSEC appears to be unsigned, which is not uncommon but does mean DNS responses do not benefit from that additional integrity layer. The domain itself is several years old, but this is a hosted subdomain on vercel.app rather than a long-established standalone brand domain. In this context, the main technical concern is not certificate validity or hosting quality, but the apparent use of cloud-hosted infrastructure to present a branded sign-in page that has been flagged by multiple security engines.
Share your experience with this website. Was it safe? Did you encounter any issues?