I dunno that doesn't sound much worse than wellsfargo.info to me.
This is especially problematic as the 'https://' hiding also happens in the URL preview when you hover over a link (Edit: seems to happen only for longer URLs).
As many other people have said, does anyone confuse C:\command.com and http://command.com? I doubt it.
Looks like it will take you to a zip file, but won't. hovering over the link looks legit enough. I just don't think it buys you that much. /shrug
You get a pretty different result if it's just "http" and not "https" though: The zip domain looks like just the file name instead of a URL.
Really trying to understand this, I hope I don't come across as snarky or naïve.
I imagine the "conversion rate" of a .net TLD will be much lower for spammers than that of a .zip
We are slowly chipping away at defense in depth all in the name of convenience.
I could see that getting under a few people's radars, but it's not much more menacing than existing fishing tricks with lookalike urls.