doodlabs[.]world
Phishing and security check for doodlabs.world
“Nur einen Moment…”
On 24 July 2026, investigators examined the domain doodlabs.world, which was registered on 21 February 2026. The site presented the page title “Nur einen Moment…”. An SSL certificate identified as WE1 was observed, indicating the use of transport‑layer encryption. The domain has been listed on a single security blocklist and was actively blocked by the PhishDestroy service, resulting in the site being taken offline at the time of analysis.
VirusTotal records show that the domain was submitted to 93 scanning engines; none reported a detection, but the absence of detections does not confirm the domain’s safety. No additional data on the hosting provider, IP address, autonomous system number, registrar, or geographic location has been disclosed, limiting the ability to map the underlying infrastructure. Likewise, Safe Browsing, Open Threat Exchange, and commercial trust‑score services have not published public verdicts for this domain.
The limited evidence suggests that doodlabs.world was used as part of a generic phishing campaign, but the exact target audience, phishing kit, or credential‑harvesting mechanism remains unknown. Defenders should continue to monitor blocklist feeds for re‑appearance of the domain, enforce DNS‑level blocking where feasible, and incorporate the domain hash into existing threat‑intel platforms. Further investigation, such as passive DNS collection and host‑level traffic analysis, is recommended to uncover any associated infrastructure that may be resurrected or repurposed.
Threat Response Pipeline
Public Blocklist Status
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive