moonpay-commerce-git-henryharris-com2-1748-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-git-henryharris-com2-1748-heliofi.vercel.app
This website appears to present itself as a cryptocurrency payments and merchant onboarding page branded as “MoonPay Commerce.” Based on the page title, meta description, and visible interface, it claims to help businesses accept crypto payments through pay links, checkout widgets, subscriptions, and related commerce tools. The page includes a branded login or sign-in flow, links to documentation, and references to wallet-based access, which suggests a fintech or crypto-commerce use case.
However, the site is hosted on a long Vercel subdomain rather than an obvious primary brand domain, while also prominently using MoonPay branding and linking to commerce.moonpay.com assets. That combination may indicate a staging, preview, affiliate, or unofficial deployment, but it can also be consistent with impersonation attempts. Based on the available content, the operator is not independently identified on the page beyond the displayed MoonPay branding, so the true ownership of this specific subdomain is not fully clear from the scan alone.
Safety Assessment for moonpay-commerce-git-henryharris-com2-1748-heliofi.vercel.app
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 19 out of 91 security engines, with many classifying it as phishing or otherwise malicious, and it was also listed by a major threat database for social-engineering activity. In addition, the domain’s IP address appears on one mail-reputation blocklist, which is a weaker signal than direct phishing detections but still worth noting. Although the malware scan did not report confirmed malicious files, its generic suspicious findings on site resources do not outweigh the broader multi-engine phishing consensus.
The page also closely imitates MoonPay branding while operating from a Vercel-hosted subdomain that is not the main MoonPay domain. That mismatch may indicate a look-alike or unauthorized login page designed to collect email addresses or wallet-based sign-ins. The screenshot shows a minimal branded sign-in interface rather than a fully transparent corporate site, which can be consistent with credential-harvesting patterns.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on Vercel infrastructure and resolves to IP address 64.29.17.67 in the United States. It presents a valid SSL/TLS certificate issued by a mainstream certificate authority, with expiry in 2026-09-26. The page appears to be built with a modern JavaScript framework, likely Next.js, based on the referenced _next/static assets. DNSSEC is not enabled for the domain.
From a technical trust perspective, the presence of HTTPS alone should not be treated as proof of legitimacy. The use of a branded login-style page on a third-party hosting subdomain, combined with phishing detections from multiple security engines and a social-engineering listing, is a more significant concern than the otherwise standard hosting and certificate setup.
Share your experience with this website. Was it safe? Did you encounter any issues?