It is well-known. uBlock blocks anything ending in ".com.com" by default. It's on most badware block lists.
It's not a hole in the web any more than people accidentally typing "fcaebook.com" is a hole in the web. It's just someone exploiting user error, not unlike domain squatting. If you hit "CTRL+ENTER" in most browsers' address bars, they used to blindly append ".com" onto the domain name. If you typed "facebook.com" and then hit CTRL+ENTER, you'd get to facebook.com.com. As far as I know, all browsers have fixed that.
This isn't actually phishing (as far as I know) because it's not trying to trick you into thinking you've gone to the correct website. It's just a malware distribution page.
I believe OpenDNS also blocks this, for the record.