moonpay-commerce-lk7s2vg21-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-lk7s2vg21-heliofi.vercel.app
This domain presents itself as a cryptocurrency payments and commerce portal branded as "MoonPay Commerce." The page title and meta description suggest a service for accepting crypto payments through pay links, checkout widgets, subscriptions, and deposits. The screenshot shows a minimalist login or onboarding page asking for an email address and offering wallet sign-in, which is consistent with a financial-technology or crypto-payment workflow.
However, the site is hosted on a Vercel subdomain rather than an obvious primary MoonPay-owned domain, even though it references commerce.moonpay.com and MoonPay-themed assets. Based on the branding and layout, it appears intended to resemble or replicate a MoonPay commerce interface. That could indicate a promotional microsite, a development deployment, or a look-alike page attempting to capture user credentials or wallet interactions.
Safety Assessment for moonpay-commerce-lk7s2vg21-heliofi.vercel.app
Several strong risk indicators are present at the time of this scan. Most notably, 16 out of 91 security engines flagged the URL, with many classifying it as phishing or otherwise malicious. The domain also closely resembles MoonPay branding while operating from a long, non-official-looking Vercel subdomain, which may indicate a look-alike page rather than a primary service domain. In the screenshot, the page requests an email address and offers wallet sign-in, a pattern that can be sensitive when presented on an unofficial or ambiguous host.
At the same time, some signals were less severe: the malware scan did not identify flagged files, and major content-malice threat databases listed in the scan were clean at the time of review. There was also one mail-reputation blocklist listing for the IP address, which is a weaker signal and does not by itself prove harmful website content. Even so, the multi-engine phishing consensus and the branding mismatch are more significant than the clean file scan in this case.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served over HTTPS with a valid TLS certificate issued by a mainstream certificate authority, and it is hosted on Vercel infrastructure with nameservers pointing to vercel-dns-3.com. The page appears to use a modern JavaScript application stack, likely Next.js, based on the referenced _next/static assets. DNSSEC is unsigned, which is common but means DNS responses do not appear to have DNSSEC validation protection.
From an infrastructure perspective, the main concern is not the certificate itself but the hosting pattern and branding context: a branded financial or crypto-related login page on a Vercel subdomain can be consistent with temporary deployments or impersonation pages. The scan also noted one DNS-based mail-reputation listing on the IP, though that is a secondary signal and may reflect shared-hosting or email reputation issues rather than direct web malware activity.
Share your experience with this website. Was it safe? Did you encounter any issues?