moonpay-commerce-git-feat-com2-1450-com2-1448-de-7eae46-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-git-feat-com2-1450-com2-1448-de-7eae46-heliofi.vercel.app
This website appears to present itself as a cryptocurrency payments and checkout service under the name "MoonPay Commerce." Based on the page title, meta description, and visible interface, it is designed to let merchants or users accept crypto payments, create payment links, and access checkout-related tools. The landing page includes email entry and wallet sign-in options, along with links to documentation and community platforms.
The domain itself is a long Vercel-hosted subdomain rather than a primary branded domain, which is unusual for a production financial or payments service. The page references assets associated with hel.io and mentions MoonPay branding, suggesting it may be imitating or mirroring a crypto-commerce product experience rather than operating from an official main corporate web address.
Based on the branding and content shown, the site appears to target users interested in cryptocurrency commerce, merchant payments, or wallet-based sign-in flows. However, the hosting pattern and domain structure may warrant additional scrutiny when compared with what users would typically expect from an established financial technology brand.
Safety Assessment for moonpay-commerce-git-feat-com2-1450-com2-1448-de-7eae46-heliofi.vercel.app
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 13 out of 91 security engines, with many of those detections classifying it as phishing or malicious. In addition, the page visually presents MoonPay branding while operating from a long third-party hosting subdomain on vercel.app rather than an obvious primary brand domain, which may be consistent with a look-alike or impersonation setup intended to collect user credentials or wallet access.
The malware scan did not identify flagged files on the page itself, which can happen when phishing pages rely on simple front-end content rather than overt malware payloads. Blacklist-style threat databases were largely clean at the time of this scan, but the domain's IP address was listed on one mail-reputation blocklist, which is a weaker signal and does not by itself prove harmful website content. Even so, the multi-engine phishing consensus is a much stronger indicator here than the clean file scan.
The site also has a very low reported trust score and no meaningful traffic ranking, which may further increase caution. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on Vercel infrastructure and resolves to IP address 64.29.17.3 in the United States. It uses a valid SSL/TLS certificate issued by Google Trust Services, with expiry shown as 2026-09-26. DNS is delegated to Vercel nameservers, and DNSSEC appears to be unsigned.
From a technical standpoint, the page appears to be a modern JavaScript application with Next.js-style static asset paths. No malicious files were flagged in the page scan, but the use of a branded financial-services presentation on a long vercel.app subdomain is a notable concern. For a payments-related service, the mismatch between branding and hosting/domain presentation may be relevant to risk assessment.
Share your experience with this website. Was it safe? Did you encounter any issues?