moonpay-commerce-git-fix-com2-1865-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-git-fix-com2-1865-heliofi.vercel.app
This domain appears to host a page branded as “MoonPay Commerce,” presenting itself as a cryptocurrency payments or checkout service for merchants. The page title and metadata describe features such as pay links, checkout widgets, subscriptions, and instant crypto deposits, which places it in the financial-services and cryptocurrency payments space.
However, the site is not using an official-looking MoonPay-owned domain. Instead, it is served from a long subdomain on vercel.app, which suggests it may be a deployed web app or landing page hosted on a cloud platform rather than a primary corporate website. The page also references assets from hel.io and includes branding elements associated with MoonPay Commerce, so it appears to be attempting to represent a crypto-commerce onboarding or sign-in experience.
Safety Assessment for moonpay-commerce-git-fix-com2-1865-heliofi.vercel.app
This website shows several notable risk indicators at the time of this scan. It was flagged by 14 out of 91 security engines, and multiple web-classification providers categorized it as phishing or fraud-related. The page is also presented on a third-party hosting subdomain rather than an obvious official corporate domain, while visually using MoonPay branding and a sign-in flow. That combination may indicate an attempt to imitate a legitimate financial or cryptocurrency service.
The malware scan did not detect malicious files on the page itself, and major content-malice blocklists listed in the scan were clean at the time of review. However, those cleaner signals are outweighed here by the multi-engine phishing consensus and the page’s branding pattern. In addition, the domain’s IP address is listed on one mail-reputation blocklist, which is a weaker signal on its own but still worth noting.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on Vercel infrastructure and resolves to IP address 64.29.17.3 in the United States. It uses a valid TLS certificate issued by Google Trust Services, with expiry shown as 2026-09-26. DNSSEC appears to be unsigned, which is common but means DNS responses do not benefit from DNSSEC validation.
From a web-stack perspective, the page appears to be a modern JavaScript application, likely built with Next.js, based on the referenced _next/static assets. The use of valid HTTPS and mainstream hosting does not by itself establish legitimacy, since phishing pages can also be deployed on reputable cloud platforms. A referenced external domain was marked with a generic suspicious heuristic, but that signal alone appears lower confidence than the broader phishing detections.
Share your experience with this website. Was it safe? Did you encounter any issues?