.zip top level domains being used in cyber attacks
ghacks.net
ghacks.net
I think people are more worried about TLDs like .zip (and .app) since they look familiar to normal users and they routinely click on those and don't think about them being a valid URL now.
Because of that, as unfair as it is, to this day when I see one of the extended TLDs, I get more suspicious about the site. I tend to avoid them unless I'm very sure they're legit.
NY's transit agency - the MTA - used (and still uses) the domain mta.info. My high school blocked that domain, along with every other info domain.
I have a .xyz domain that I briefly wanted to use for email, but services blocked it based entirely off the TLD. Using the same mail service (fastmail) I could send mail from my .net domains.
It is interesting that $15 a year is enough savings to justifying starting a new phishing attempt. I assumed there was so much money in phishing that an extra ~$1.05 a month could be easily absorbed.
Either way, I'm shocked that a .zip domain was ever approved. This should have been obvious for whatever mysterious board approves TLDs.
https://en.wikipedia.org/wiki/List_of_Internet_top-level_dom...