moonpay-commerce-git-fix-com2-1089-disabled-netw-b80dff-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-git-fix-com2-1089-disabled-netw-b80dff-heliofi.vercel.app
This domain appears to host a web page presenting itself as "MoonPay Commerce," a cryptocurrency payments and checkout service. The page title, meta description, and visible content suggest it is aimed at merchants who want to accept crypto payments, with references to pay links, checkout widgets, subscriptions, and wallet-based sign-in.
Based on the page assets and linked resources, the site appears to be deployed on Vercel and uses branding elements associated with MoonPay and Helio. The domain itself is a long Vercel subdomain rather than an obvious primary corporate domain, which may indicate a preview, staging, campaign, or unofficial deployment rather than a standard production website.
The page layout shown in the screenshot is minimal, featuring an email entry field, a wallet sign-in option, and links to policy pages. While it resembles a fintech or cryptocurrency onboarding page, the available data does not independently confirm that it is operated by MoonPay or an authorized partner.
Safety Assessment for moonpay-commerce-git-fix-com2-1089-disabled-netw-b80dff-heliofi.vercel.app
Multiple security signals raise concern around this page at the time of this scan. It was flagged by 13 out of 91 security engines, with many of those detections classifying it as phishing or otherwise malicious. The domain also presents branding associated with MoonPay while using a long third-party hosting subdomain, which may increase the risk of brand imitation or credential-harvesting behavior, especially for a page requesting email input and offering wallet sign-in.
At the same time, some checks were less severe: the malware scan did not identify flagged files, and major content-malice threat databases listed in the scan were clean at the time of review. However, the domain's IP address was listed on one mail-reputation blocklist, which is a weaker signal than direct phishing detections but still worth noting. A referenced external domain was also marked by a heuristic scanner, though that alone would be low-confidence without broader corroboration.
Taking the stronger signals first, the multi-engine phishing consensus is the most important factor here. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on Vercel infrastructure and resolves to IP address 216.198.79.195 in Walnut, United States. It uses a valid TLS certificate issued by Google Trust Services, with expiry shown as 2026-09-26. The page appears to be built with a modern JavaScript framework, likely Next.js, based on the referenced static asset paths.
DNSSEC appears to be unsigned, which is common but provides less DNS-layer integrity protection than a signed configuration. No malicious files were identified in the file scan, but the combination of third-party hosting, brand-themed assets, and phishing detections from multiple security engines suggests the technical delivery setup may be being used in a way that warrants caution at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?