moonpay-commerce-9secgu53s-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-9secgu53s-heliofi.vercel.app
This domain appears to present itself as a MoonPay Commerce login or onboarding page related to cryptocurrency payment processing. The page title and meta description describe a service for accepting crypto payments through pay links, checkout widgets, subscriptions, and deposits, and the screenshot shows a branded sign-in interface asking for an email address or wallet-based login.
Based on the visible branding and referenced domains, the page may be attempting to associate itself with MoonPay, a known crypto payments brand, while being hosted on a vercel.app subdomain rather than an obvious primary MoonPay domain. The site also references assets from hel.io and commerce.moonpay.com, which suggests it may be imitating or reusing branding from legitimate crypto-commerce infrastructure. At the time of this scan, it appears to function as a financial-services or cryptocurrency-related landing and sign-in page rather than a full informational website.
Safety Assessment for moonpay-commerce-9secgu53s-heliofi.vercel.app
Multiple independent security signals raise concern about this domain at the time of this scan. It was flagged by 16 out of 91 security engines, and several web-classification providers categorized it as phishing or fraud-related content. The page also uses MoonPay branding while operating from a long, non-primary vercel.app subdomain, which may indicate an attempt to resemble a legitimate financial service login page rather than using an official brand-owned web address.
The malware scan did not report confirmed malicious files, but it did attach a generic suspicious heuristic to the domain and several static assets. Generic heuristic findings alone are low-confidence, yet in this case they are outweighed by the broader multi-engine phishing consensus. In addition, the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal than phishing detections but still adds a small amount of caution.
Because this page appears to request sign-in details for a crypto-payment service and has substantial phishing-related detection coverage, visitors should treat it carefully and independently verify the address before entering credentials or connecting a wallet. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on Vercel infrastructure and resolves to IP address 64.29.17.131 in the United States. It uses a valid SSL/TLS certificate issued by Google Trust Services, with expiry shown as 2026-09-26, which indicates encrypted transport was available at the time of the scan. The web stack appears to be a modern JavaScript application, with multiple Next.js static chunk files and external assets loaded from hel.io.
DNSSEC is unsigned, so DNS responses do not appear to benefit from DNSSEC validation. While the certificate and hosting setup look technically standard for a cloud-hosted web app, those factors do not by themselves establish legitimacy. The main technical concern here is not transport security but the combination of brand-style presentation, credential-collection behavior, and broad phishing-related detections.
Share your experience with this website. Was it safe? Did you encounter any issues?