> Can you quickly tell which of the URLs below is legitimate and which one is a malicious phish that drops evil.exe?<p>Yes? When you hover the first link the browser says "v1271.zip", and when you hover the second link it says "<a href="https://github.com/kubernetes/kubernetes/archive/refs/tags/v1.27.1.zip">https://github.com/kubernetes/kubernetes/archive/refs/tags/v...</a>"<p>You don't even need a .zip domain to do this, just assign a misleading link i.e. [google.com](badsite.com). If the argument is going to be no one looks at the on hover link preview, then why bother even paying for a .zip domain in the first place? Going further, you can also just buy a similar domain to confuse people, which might even work better than buying the .zip since then you _might_ even catch careful people that glance at the on hover preview.