Phishing
This site is classified as Phishing based on multiple risk signals, including 13 blacklist detections, no established public user-review history, and phishing-related signals. These risks are driven by active warning signals despite the site's longer domain history.
How we scored uae.ap1.shop
Tech signals:
Web Application, UniApp Framework, Cloudflare Browser Insights, Vue.js Framework
Negative signals:
security-provider warnings
multiple malware or phishing blacklist detections (12)
a low third-party reputation score
phishing-style impersonation signals
heuristic signals associated with phishing
limited independent reputation data
automated caution checks
the exact application implements a deposit-based task scam
the platform collects credentials and financial-account data
the public backend links a multi-country retail-impersonation network
Positive signals:
a long-term domain history (4.8 years)
an active SSL certificate (3 months)
Last checked October 1, 2026 at 10:52 AM by
Gridinsoft Trust Model v2.5.5
Share this report?
Independent Gridinsoft analysis
What Gridinsoft observed on uae.ap1.shop
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
Current review
Review ID
GMA-20260826043915-9b3b04cf
Reviewed
by Gridinsoft Threat Analyst
Analyst finding
Phishing
Evidence basis
First-party site analysisExternal vendor intelligence: Context only — not used for this decision
The exact host is a malicious financial phishing and task-scam application. It solicits credentials, deposits, payment vouchers, bank details, and withdrawal passwords through a VIP commission and matched-order workflow with frozen-account states. The customer screenshot shows active AED deposits in the same flow, and the live public backend links the site to a broader multi-country retail-impersonation network. The current Phishing classification should be retained.
Analyst findings
Critical1
High2
Critical01
The exact application implements a deposit-based task scam
The application combines invitation registration, VIP tiers, matched tasks or orders, promised commissions, minimum balances, repeated top-ups, frozen states, payment-voucher uploads, and withdrawals. The customer's exact AED deposit history confirms that the financial deposit workflow is in active use.
High02
The platform collects credentials and financial-account data
The current code requests phone and login credentials, bank-account details, payment vouchers, and a separate withdrawal password. The public configuration also enables plaintext withdrawal-password display, creating a direct account and financial-data risk.
High03
The public backend links a multi-country retail-impersonation network
The same live API links related invitation-registration hosts across countries and retail-themed names, including SHEIN, Alibaba, and noon variants. This is infrastructure-level evidence from the operator's own backend, not merely a domain blacklist label.
Review 4 documented observations
View evidence
01Content
The exact host returned HTTP 200 and loaded a mobile single-page application whose current code implements invitation-only registration, login, VIP levels, matched shopping tasks or orders, commission balances, top-ups, payment-voucher uploads, bank-account collection, withdrawal passwords, frozen orders, and withdrawal workflows. These functions form the characteristic deposit-and-task loop of a task scam rather than a normal retail checkout.
HTTP status200
Final URLhttps://uae.ap1.shop/
Page elementRegistration requests a phone number, login password, confirmation, and invitation code.
Page elementThe application exposes VIP levels, commission rates, task or order matching, minimum balances, recharge, payment-voucher upload, bank details, and withdrawal passwords.
Analyst observationThe public code includes frozen-order and customer-service-to-unfreeze states.
02Content
The unauthenticated same-host API returned live configuration for the task platform. It enabled referral commissions, task limits, automatic freezing and unfreezing, VIP upgrades, deposits, withdrawals, bank-account collection, and plaintext withdrawal-password display. Its platform identity was internally inconsistent, and the country list linked related registration hosts using SHEIN, Alibaba, noon, and other retail-themed names across multiple countries.
HTTP status200
Public artifact URLhttps://uae.ap1.shop/api/mall/common/getSysParamConfig
Public artifact URLhttps://uae.ap1.shop/api/mall/common/country/list
Page elementThe configuration identified a Chinese platform name, Dominican Republic country value, ETB currency, and an unrelated mooncity.top website.
Page elementRelated country entries linked registration sites on shein-vip.shop, alibaba-vip.shop, noon-vip.store, ap1.shop, and other domains.
03Content
The customer-supplied screenshot shows the application's Bill page with Top up and Withdraw tabs, a new AED 300 deposit marked Pending review, and earlier AED 65, AED 50, and AED 20 deposits marked Recharge successful. This exact supplied object is consistent with the deposit history implemented by the reviewed application.
Page elementEarlier AED 65, AED 50, and AED 20 deposits are shown as Recharge successful.
04Historical content
Public URL-scan records show six exact-host submissions from May through July 2026, mainly the same invitation-code registration URL and one bank-card-edit path. Parent-domain results also show related country subdomains with invitation registration pages. OTX collections mention task scams and retail-brand impersonation, while Wayback returned no successful exact-host HTML capture.
Analyst observationSix exact-host URL-scan records included repeated registration submissions with invitation code JCNFDY7N and a bank-card-edit path.
Analyst observationParent-domain URL-scan records included bd.ap1.shop, om.ap1.shop, and gt.ap1.shop registration pages.
Analyst observationNo successful exact-host HTML snapshot was returned by Wayback.
Scope and limitations
No account was created, no credentials or bank details were submitted, and no further payment or withdrawal was attempted by Gridinsoft.
The review did not identify the real-world identity of the operator or determine whether any specific payment can be recovered.
Public URL-scan, threat-intelligence, search, and archive indexes are incomplete; the verdict does not depend on their completeness.
The verdict applies to uae.ap1.shop and the exact reviewed application and backend evidence; related hosts require their own current object-level review.
What is Uae.ap1?
We flagged Uae.ap1.shop as phishing. The page behavior matches a common credential-theft flow: impersonation first, urgency second, data request last.
Typical prompts on sites like this include account alerts, failed-delivery notices, or "verify now" dialogs asking for passwords, card numbers, or one-time codes. Do not submit credentials here. Open the real service in a new tab and check your account directly.
This domain was registered November 25, 2021 at 10:50 PM through the company unknown
and ownership information is not publicly available.
Complaint contact not found.
Is uae.ap1.shop safe?
— Unfortunately, not likely.
🚨
Gridinsoft blocks this website because it was classified as phishing.
uae.ap1.shop should not be treated as a safe website. Gridinsoft gives it a 1/100 trust score, and publicly displayed security sources report 13 warning(s). Avoid entering passwords, personal details, or payment data.
Why is uae.ap1.shop marked "Phishing"?
Gridinsoft evaluates uae.ap1.shop, focusing on limited website popularity, suspicious content indicators (Blacklisted by Security Providers, Phishing - High Risk, Heuristic - Phishing), hosting technology and infrastructure, SSL certificate status, website reputation across multiple databases, customer reviews from various independent platforms. We weigh these indicators to calculate the trust score.
Note: Automated systems are not perfect — while the evidence suggests risk, there is still a chance the site is legitimate. We recommend you check the website using detailed analysis or by contacting the company directly through verified channels.
A structured view of the site's detected themes, page signals, and related online footprint elements.
Web Application
This site is configured as an installable web application (PWA-style behavior) with app-like interaction patterns.
UniApp Framework
This site uses the UniApp framework that allows developers to build applications for mobile (iOS, Android), web, and mini-programs (e.g., WeChat) using a single codebase based on Vue.js.
Cloudflare Browser Insights
This website is proxied through Cloudflare's CDN/network and has Cloudflare Browser Insights enabled.
Vue.js Framework
Blacklisted by Security Providers
Security intelligence signal: A security-provider signal contributes to the automated assessment of uae.ap1.shop. Publicly displayable provider verdicts, when available, are reported separately; some source details may be restricted by license.
Phishing - High Risk
Automated analysis detected strong patterns on this site associated with phishing or brand impersonation. Exercise extreme caution and avoid entering passwords, verification codes, payment details, or personal information until legitimacy is independently confirmed.
Heuristic - Phishing
Heuristic Risk
Established Domain
ap1.shop has maintained active domain presence over time, indicating operational continuity.
Listed by Gridinsoft
Gridinsoft Internet Security classified this site as unsafe. As a VirusTotal partner, our detections contribute to broader protection across tools and browsers.
Low Scamadviser Score
Independent security assessment from Scamadviser indicates this site has received a low trust rating, suggesting potential security risks or operational concerns requiring user caution.
External provider warnings: 13/28 Phishing
This section shows what independent external security sources say about this site.
A warning appears when one or more sources report malware, phishing, abuse, or other safety concerns. Each row shows the source and its verdict.
If no source reports a warning, the site is shown as clear in this section.
alphaMountain.ai
Phishing
CRDF
Malicious
CyRadar
Phishing
Forcepoint ThreatSeeker
Phishing
Fortinet
Phishing
G-Data
Phishing
Lionic
Phishing
Sophos
Phishing
VIPRE
Phishing
Webroot
Malicious
Scamadviser
Warned
BitDefender
Warned
ESET
Suspicious
External provider results for Uae.ap1.shop, last checked September 30, 2026.
— VirusTotal
Domain Information
CreatedNovember 25, 2021 at 10:50 PM
Domain Age4.8 years
Top Level Domain.shopGeneric TLD
Subdomainuae
Technical Details
IP Address172.67.170.107
Hosting ProviderAS13335 Cloudflare, Inc.San Francisco, California, US
SSL CertificateYE2TLSv1.3 · Valid for: 3 months · from September 8, 2026 at 3:25 PM · to December 7, 2026 at 3:25 PM
Content from the analyzed website
Quoted for security analysis. These statements belong to the source website and are not endorsed by Gridinsoft.
Scammers have devised new ways to deceive users, and what was relevant ten years ago may not be applicable today. In this post, we have compiled the most current types of online scams.
If you own Uae.ap1.shop and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.
A website report warns you. A PC scan protects you.
Unsafe sites can leave adware, unwanted apps, or hidden malware in downloads and browser settings. Run Gridinsoft Anti-Malware to check what may already be on this Windows PC.
Checks active threats, startup items, and suspicious downloads
Finds adware and unwanted apps linked to unsafe websites
Shows scan results before you decide what to remove
Your comment is currently undergoing moderation and will be published shortly.
Help protect others by sharing this page on social media! The more people who know about uae.ap1.shop, the fewer chances they have to deceive someone else.Help others evaluate uae.ap1.shop by sharing this page on social media!
Help protect others by sharing this page on social media! The more people who know about uae.ap1.shop, the fewer chances they have to deceive someone else. Help others evaluate uae.ap1.shop by sharing this page on social media!