moonpay-commerce-git-henryharris-com2-2322-light-e25621-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-git-henryharris-com2-2322-light-e25621-heliofi.vercel.app
This domain presents itself as a MoonPay Commerce page focused on cryptocurrency payments. The page title and metadata describe a service for accepting crypto through pay links, checkout widgets, deposits, subscriptions, and related e-commerce use cases. The screenshot shows a minimalist login-style landing page with an email entry field, a wallet sign-in option, and branding that resembles MoonPay Commerce.
Based on the domain structure, this is not hosted on MoonPay's primary domain but on a Vercel subdomain with a long project-style name. The page also references assets associated with hel.io and includes a link to commerce.moonpay.com, which suggests it may be imitating or mirroring branding from a legitimate crypto payments platform rather than operating as an official primary website.
The site appears to target merchants or users interested in crypto-enabled commerce rather than functioning as a conventional online store. Its purpose seems to be account access, onboarding, or lead capture for a crypto payment service, although the unusual hosting pattern and branding context warrant caution.
Safety Assessment for moonpay-commerce-git-henryharris-com2-2322-light-e25621-heliofi.vercel.app
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 9 out of 91 security engines, with several classifying it as phishing or malicious. In addition, the page closely imitates MoonPay Commerce branding while operating from a long Vercel-hosted subdomain rather than an obvious official MoonPay web address, which may indicate a look-alike page intended to collect email addresses or wallet-based sign-ins.
The malware scan did not detect malicious files in the sampled page resources, and major content-focused threat databases listed in the scan were largely clean at the time of review. However, that does not outweigh the multi-engine phishing consensus. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal and may relate to hosting or sender reputation rather than website content, but it still adds a small amount of caution.
Taken together, the strongest indicators here are the phishing detections, the impersonation-style branding, the credential-collection interface, and the use of a third-party hosting subdomain instead of a clearly official brand domain. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid TLS certificate issued by Google Trust Services, with hosting on Vercel infrastructure and a reported server IP of 64.29.17.131 in the United States. Nameservers also point to Vercel-managed DNS, and DNSSEC appears to be unsigned. The page loads modern static assets consistent with a JavaScript web application, likely built with a framework such as Next.js.
From a technical standpoint, the presence of HTTPS is positive but should not be treated as proof of legitimacy. A notable concern is that the page is served from a branded-looking Vercel subdomain rather than a straightforward official corporate domain, which is a common pattern in temporary deployments, previews, or impersonation pages. No malicious files were flagged in the provided file scan, but the broader reputation data suggests caution despite the clean resource scan.
Share your experience with this website. Was it safe? Did you encounter any issues?