WELLSFARGO ALERT: Suspicious activity detected in your account! Please see the attachment for more information [https://wellsfargo.zip]
As many other people have said, does anyone confuse C:\command.com and http://command.com? I doubt it.
Looks like it will take you to a zip file, but won't. hovering over the link looks legit enough. I just don't think it buys you that much. /shrug
You get a pretty different result if it's just "http" and not "https" though: The zip domain looks like just the file name instead of a URL.
I dunno that doesn't sound much worse than wellsfargo.info to me.
This is especially problematic as the 'https://' hiding also happens in the URL preview when you hover over a link (Edit: seems to happen only for longer URLs).