moonpay-commerce-r5fqezbru-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-r5fqezbru-heliofi.vercel.app
This domain hosts a page that appears to present itself as "MoonPay Commerce," a cryptocurrency payments and checkout service aimed at merchants. The page title and meta description describe features such as pay links, checkout widgets, subscriptions, and instant crypto payments, and the screenshot shows a login-style landing page asking for an email address or wallet sign-in.
Based on the domain structure, this is not the primary moonpay.com domain but a subdomain hosted on vercel.app. The page also references assets from hel.io and includes branding elements associated with MoonPay Commerce. That combination may indicate a promotional, staging, partner, or cloned deployment, but based on the available data alone, the exact operator of this specific Vercel-hosted instance cannot be independently confirmed.
Safety Assessment for moonpay-commerce-r5fqezbru-heliofi.vercel.app
Several risk indicators are present at the time of this scan. The domain was flagged by 14 out of 91 security engines, with multiple sources classifying it as phishing or fraud-related. In addition, several web-classification providers categorized the site as phishing or financial fraud, even though one provider labeled it as financial services. The page visually resembles a legitimate crypto-commerce login or onboarding portal, which can increase the risk of credential harvesting if the deployment is not officially controlled by the brand it references.
There are also mixed technical signals. A malware scan did not detect malicious files on the page itself, which suggests the concern may be more about deceptive content or impersonation than about drive-by malware delivery. At the same time, the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal than direct phishing detections but still worth noting. The use of a Vercel-hosted subdomain rather than a primary branded domain, combined with the strong multi-engine phishing consensus, materially raises concern.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by a mainstream certificate authority, with expiry shown in September 2026. It is hosted on Vercel infrastructure and resolves to an IP address in the United States. The page appears to be built with a modern JavaScript framework, with static assets served from Next.js-style paths and additional resources loaded from hel.io.
DNSSEC appears to be unsigned, which is common but means DNS responses do not benefit from that extra integrity layer. No malicious files were flagged in the provided file scan, and no iframes were reported. However, the main technical concern is not transport security but the possibility that this branded login-style page may be a deceptive deployment hosted on third-party infrastructure.
Share your experience with this website. Was it safe? Did you encounter any issues?