Analysis indicates that graniteassets.com is currently active and associated with a high‑risk generic phishing campaign. The domain resolves to the Cloudflare‑hosted address 104.21.49.125, which is located in Canada and is served by the nameservers curt.ns.cloudflare.com and nena.ns.cloudflare.com. Registration information shows the domain was created on 16 October 2011 through the registrar Gname.com Pte. Ltd., suggesting a long‑standing registration that may be leveraged to evade rapid takedown.
The domain is listed on three public security blocklists and is actively blocked by the PhishDestroy, MetaMask, and SEAL filtering platforms, confirming that multiple sink‑hole and anti‑phishing services have observed malicious use. VirusTotal reports that the domain has been scanned by 91 AV vendors without any current detections; this absence of detections does not constitute evidence of benign behavior and should be interpreted as a lack of current signatures rather than safety. No public Safe Browsing, OTX, SSL certificate details, HTTP status codes, or page‑title information are available in the supplied intelligence, leaving the exact content and payload of the site unverified.
Given the observed infrastructure, defenders should enforce DNS‑level blocking of graniteassets.com, incorporate the associated IP address 104.21.49.125 into network deny lists, and ensure email security gateways flag any communications referencing the domain. Continuous monitoring of the domain’s resolution and blocklist status is advised, as well as periodic re‑scanning with updated AV engines to capture any newly developed payloads. Organizations should also consider reporting any observed phishing attempts to the blocking services already engaged (PhishDestroy, MetaMask, SEAL) to aid collective mitigation.