moonpay-commerce-dcla69ceg-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-dcla69ceg-heliofi.vercel.app
This domain appears to present itself as a cryptocurrency payments and checkout page branded as “MoonPay Commerce.” The page title and metadata describe a service for accepting crypto payments through pay links, checkout widgets, deposits, subscriptions, and related e-commerce use cases. The screenshot shows a minimalist login or onboarding interface asking for an email address or wallet sign-in, along with links to documentation and policy pages.
Based on the domain structure, this is not hosted on MoonPay’s primary corporate domain but on a vercel.app subdomain. The page also references assets associated with hel.io and mentions MoonPay branding, which may indicate a promotional, embedded, partner, or cloned implementation rather than an official primary MoonPay property. Given the financial-services theme and wallet sign-in flow, visitors may be prompted to submit credentials or connect a crypto wallet.
Safety Assessment for moonpay-commerce-dcla69ceg-heliofi.vercel.app
This website shows multiple risk indicators at the time of this scan. It was flagged by 18 out of 91 security engines, and multiple web-classification providers categorized it as phishing or fraud-related. In addition, a major threat database listed the URL for social-engineering activity. Those are stronger signals than a clean file-based malware scan, especially for phishing pages, which often do not contain traditional malicious files.
The domain name and page presentation closely resemble MoonPay branding while operating from a third-party hosting subdomain rather than an obvious official MoonPay web property. That resemblance may indicate a look-alike page intended to collect email addresses, wallet connections, or other sensitive financial information. The domain’s IP address is also listed on one mail-reputation blocklist, which is a weaker signal on its own but still adds minor caution.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on Vercel infrastructure and resolves to IP address 64.29.17.131 in the United States. It uses a valid TLS certificate issued by Google Trust Services, with expiry shown as 2026-09-26. DNSSEC appears to be unsigned, which is common but means DNS responses do not benefit from DNSSEC validation.
From a web-stack perspective, the page appears to be a modern JavaScript application using Next.js-style static assets. The malware scan reported 0 flagged files out of 11 scanned, and no flagged external links or iframes were identified in that specific crawl. However, the stronger concern here is not executable malware but the possibility of credential or wallet-harvesting behavior suggested by the branding, hosting context, and phishing-related detections.
Share your experience with this website. Was it safe? Did you encounter any issues?