moonpay-commerce-p1n7nv04q-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-p1n7nv04q-heliofi.vercel.app
This domain appears to present itself as a MoonPay Commerce login or onboarding page related to cryptocurrency payments. The page title and visible content reference "MoonPay Commerce" and describe services such as accepting crypto payments, pay links, checkout widgets, deposits, subscriptions, and wallet-based sign-in. The layout is minimal and includes an email entry field, a wallet sign-in option, and links to documentation and social platforms.
Based on the domain structure, this is not hosted on MoonPay's primary corporate domain but on a Vercel subdomain that includes both "moonpay-commerce" and "heliofi" in the hostname. Referenced assets also include domains associated with hel.io and commerce.moonpay.com, which suggests the page may be imitating or repurposing branding associated with crypto-payment services. The site appears to target users interested in merchant crypto payments or account access rather than functioning as a general informational website.
Safety Assessment for moonpay-commerce-p1n7nv04q-heliofi.vercel.app
This domain shows multiple high-risk indicators at the time of this scan. It was flagged by 20 out of 91 security engines, and multiple threat databases categorized it as phishing or social-engineering related. In addition, one major browser-protection blacklist listed the URL for social-engineering activity. While the page itself is visually polished and uses valid HTTPS, those factors do not offset the breadth of phishing-related detections in the available scan data.
The hostname also raises concern because it appears to use MoonPay branding on a third-party hosting subdomain rather than an obvious primary MoonPay web property. That kind of branding mismatch may be consistent with impersonation or credential-harvesting setups, especially when combined with a login-style interface requesting an email address or wallet sign-in. The domain's IP address is also listed on one mail-reputation blocklist, although that signal is weaker than the phishing detections and may reflect shared infrastructure rather than website content.
The malware scan did not identify malicious files in the sampled page resources, but phishing pages often rely on deceptive branding and form collection rather than downloadable malware. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on Vercel infrastructure and resolves to IP address 64.29.17.195 in the United States. It presents a valid SSL/TLS certificate issued by Google Trust Services, with expiry in September 2026. DNSSEC appears to be unsigned, which is common but means DNS responses do not benefit from DNSSEC validation.
The page appears to be built with a modern JavaScript framework, with multiple Next.js-style static assets loaded from the same Vercel-hosted subdomain and branding assets fetched from hel.io. No malicious files were flagged in the provided file scan, and no iframes were reported. However, the combination of third-party hosting, brand-themed naming, and strong phishing detections across security engines is a notable technical concern at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?