The new ".zip" domain is being used almost solely for malware. Some of the clicks are very deceptive, even to technically knowledgeable people. See the attached image for an example.
You can block all zip domains with the following uBlock Origin rule:
||zip^
Tell everyone you know.
Andreas Kilgus
•"Can you quickly tell which of the URLs below is legitimate and which one is a malicious phish that drops evil.exe?
https://github.com/kubernetes/kubernetes/archive/refs/tags/@v1271.zip
https://github.com/kubernetes/kubernetes/archive/refs/tags/v1.27.1.zip"
Hypolite Petovan likes this.
Hypolite Petovan
•.zip
top-level domain.Andreas Kilgus
•Seems to be the Fraction Slash ⁄ or the Division Slash ∕.
Hypolite Petovan
•this.ven
•Content warning: Identifying the malicious link to .zip TLD
Even the @ character wasn't suspicious as :mastodon: #Mastodon user profile URLs also use them, for example. Without directly comparing it to the same URL it's hard to distinguish the first one especially depending on the font:
https://github.com∕kubernetes∕kubernetes∕archive∕refs∕tags∕@v1271.zip ❌
https://github.com/kubernetes/kubernetes/archive/refs/tags/v1.27.1.zip ✔️
GitHub: Let’s build from here
GitHubHypolite Petovan
•Martijn Vos
•Hypolite Petovan
•