moonpay-commerce-git-henryharris-com2-2325-excha-6f0ba4-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-git-henryharris-com2-2325-excha-6f0ba4-heliofi.vercel.app
This domain hosts a page branded as "MoonPay Commerce" and presents itself as a cryptocurrency payments or checkout service. The visible content invites visitors to enter an email address or sign in with a wallet, and the metadata describes services such as pay links, checkout widgets, subscriptions, and instant crypto payments. Based on the page text and linked assets, it appears to imitate or reference a financial-services or crypto-commerce platform.
The site is served from a Vercel-hosted subdomain rather than from an obvious primary brand domain. Its structure and branding suggest it may be a deployed web app or landing page associated with crypto payments, but the unusually long subdomain naming pattern and the use of third-party hosting make ownership less clear from the domain alone. Based on available data, it appears to target users interested in cryptocurrency transactions or merchant payment tools.
Safety Assessment for moonpay-commerce-git-henryharris-com2-2325-excha-6f0ba4-heliofi.vercel.app
Multiple independent signals indicate elevated risk at the time of this scan. The domain was flagged by 14 out of 91 security engines, and several web-classification providers categorized it as phishing or fraud-related. The page also uses branding associated with a known crypto-payment service while operating from a long Vercel subdomain rather than an apparent official primary domain, which may indicate a look-alike or impersonation attempt intended to collect credentials or wallet access.
The malware scan did not detect malicious files on the page itself, which can happen when a phishing page is primarily collecting information rather than delivering malware. Blacklist checks for major content-malice databases were largely clean at the time of this scan, but the domain's IP address was listed on one mail-reputation blocklist, which is a weaker cautionary signal rather than direct proof of harmful web content. Taken together, the multi-engine phishing detections, the branding mismatch, and the login-oriented page design are more significant than the clean file scan.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on Vercel infrastructure and resolves to IP address 64.29.17.67 in the United States. It presents a valid TLS certificate issued by Google Trust Services with an expiry in 2026-09-26, which indicates encrypted transport was available at the time of testing. The page appears to be built with a modern JavaScript framework, with multiple static assets served from Next.js-style paths.
DNSSEC is unsigned, which is common but means DNS responses do not benefit from DNSSEC validation. No malicious files were flagged in the page scan, but the combination of a branded financial-style login page on a third-party hosted subdomain and the strong phishing consensus across security engines is a notable technical concern.
Share your experience with this website. Was it safe? Did you encounter any issues?