@dangillmor
I understand how .zip domains can be abused, but isn't the result just an unwanted download?
What's the current state of browser vulnerability to unwanted clicks? URL obfuscation tricks are now so old and common that almost any attempt is going to get some clicks, regardless of a file extension.