moonpay-commerce-git-feat-com2-2319-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-git-feat-com2-2319-heliofi.vercel.app
This domain appears to host a web page branded as "MoonPay Commerce," presenting itself as a cryptocurrency payments and checkout service. The page title and meta description suggest functionality for accepting crypto payments, pay links, checkout widgets, subscriptions, and instant deposits. The screenshot shows a login-style landing page with email entry and wallet sign-in options, along with links to documentation and social platforms.
Based on the domain structure, this is not the official moonpay.com domain but a Vercel-hosted subdomain: moonpay-commerce-git-feat-com2-2319-heliofi.vercel.app. The page also references assets from hel.io and includes branding elements associated with MoonPay Commerce. This combination may indicate a development, preview, or cloned deployment rather than an official production site operated directly on MoonPay's primary domain.
Safety Assessment for moonpay-commerce-git-feat-com2-2319-heliofi.vercel.app
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 13 out of 91 security engines, and several web-classification providers categorized it as phishing or fraud-related. Although some blacklist databases focused on known malware and phishing URLs did not list the domain at the time of this scan, that clean result is outweighed here by the relatively broad multi-engine phishing consensus.
The domain name itself also raises concern because it uses MoonPay branding on a third-party hosting subdomain rather than the official moonpay.com domain. The page visually presents itself as "MoonPay Commerce" and offers email and wallet sign-in, which may increase the risk of credential harvesting or wallet-targeted social engineering if visitors assume it is an official login page. In addition, the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal than phishing detections but still worth noting.
The malware scan did not flag malicious files on the page itself, and one referenced external domain received only a generic heuristic alert, which on its own would be low confidence. However, based on the combination of repeated phishing classifications, the branding mismatch, and the login-focused content, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by a mainstream certificate authority, with expiry shown as 2026-09-26. It is hosted on Vercel infrastructure and resolves to an IP address in the United States. The page appears to be built with a modern JavaScript framework, with multiple static assets served from _next paths, which is consistent with a Next.js deployment.
DNSSEC appears to be unsigned, which is common but provides less DNS-layer integrity assurance than a signed configuration. The hosting setup and certificate validity do not by themselves indicate legitimacy, especially for branded login pages deployed on shared cloud platforms. In this case, the main technical concern is not transport security but the apparent use of brand-related content on a non-official hosted subdomain.
Share your experience with this website. Was it safe? Did you encounter any issues?