moonpay-commerce-git-henryharris-com2-1363-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-git-henryharris-com2-1363-heliofi.vercel.app
This domain appears to host a page branded as "MoonPay Commerce," presenting itself as a cryptocurrency payments or checkout service for merchants. The page title and meta description suggest functionality related to accepting crypto payments, pay links, checkout widgets, subscriptions, and instant deposits, which places it in the financial-services and cryptocurrency payments space.
However, the hostname is a long subdomain on vercel.app rather than an obvious primary brand domain, and the page references branding assets associated with MoonPay. Based on the available content and domain structure, this page appears to be a hosted deployment that may be imitating or reproducing a branded crypto-commerce login or onboarding interface rather than serving as a clearly established official corporate website.
Safety Assessment for moonpay-commerce-git-henryharris-com2-1363-heliofi.vercel.app
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 19 out of 91 security engines, with many classifying it as phishing or fraud-related, and it was also listed by a major threat database for social-engineering activity. In addition, the domain's IP address appears on one mail-reputation blocklist, which is a weaker signal on its own but still worth noting as part of the overall picture.
The page visually presents a branded "MoonPay Commerce" sign-in or onboarding experience and uses a domain name that embeds the MoonPay brand within a third-party hosting subdomain. That kind of branding/domain mismatch may be consistent with look-alike or impersonation activity, especially for a page requesting an email address or wallet sign-in in a financial context. Although the malware scan did not detect malicious files at the time of analysis, phishing pages often contain little or no overt malware and instead rely on credential capture or wallet-related social engineering.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on Vercel infrastructure and resolves to IP address 64.29.17.3 in the United States. It presents a valid SSL/TLS certificate issued by Google Trust Services, expiring in 2026-09-26. DNS uses Vercel nameservers, and DNSSEC appears to be unsigned.
From a web-application perspective, the page appears to be a modern JavaScript deployment using Next.js-style static assets. The certificate validity indicates encrypted transport, but HTTPS alone does not verify the legitimacy of the content. The main technical concern here is not TLS configuration but the combination of third-party hosting, brand-themed presentation, and strong phishing-related reputation signals at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?