moonpay-commerce-pm9rgtd8y-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-pm9rgtd8y-heliofi.vercel.app
This website appears to present itself as a cryptocurrency payments and checkout service under the name "MoonPay Commerce." Based on the page title, meta description, and visible branding, it claims to help merchants accept crypto payments through pay links, checkout widgets, subscriptions, and related commerce tools. The page includes an email entry field and a wallet sign-in option, suggesting it is intended as a login or onboarding portal rather than a general informational homepage.
The domain itself is hosted on a vercel.app subdomain rather than an apparent primary corporate domain, while the page references assets from hel.io and mentions MoonPay branding. That combination may indicate a campaign, microsite, staging deployment, partner integration, or an unofficial page imitating a known crypto-payment brand. Based on the available content, the site appears to target users interested in cryptocurrency commerce services and merchant payment flows.
Safety Assessment for moonpay-commerce-pm9rgtd8y-heliofi.vercel.app
Several security signals raise concern about this page at the time of this scan. The URL was flagged by 14 out of 91 security engines, with multiple detections describing it as phishing or malicious. In addition, the domain closely resembles branding associated with a known crypto payments company while operating from a third-party hosting subdomain, which may indicate a look-alike page intended to capture email addresses or wallet-based sign-ins.
The malware scan did not identify flagged files on the page itself, and major content-malice threat databases listed in the scan were clean at the time of review. However, the domain's IP address was listed on one mail-reputation blocklist, which is a weaker signal than direct phishing detections but still worth noting. The page also references an external domain that received a generic heuristic flag, though that finding alone would be low confidence.
Taken together, the multi-engine phishing consensus, the brand-like presentation, and the credential-collection style landing page outweigh the cleaner file-scan results. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on Vercel infrastructure and resolves to IP address 64.29.17.195 in the United States. It uses a valid TLS certificate issued by a mainstream certificate authority, with expiry shown as 2026-09-26. DNS is delegated to Vercel nameservers, and DNSSEC appears to be unsigned.
From a technical standpoint, the page appears to be a modern JavaScript application with Next.js-style static asset paths. The use of valid HTTPS and reputable cloud hosting does not by itself establish legitimacy, since phishing pages may also use standard cloud platforms and valid certificates. A notable concern here is the mismatch between the branded content and the hosted subdomain structure, which may make origin verification harder for end users.
Share your experience with this website. Was it safe? Did you encounter any issues?