If https://microsoft-office.zip can fool people then why not https://microsoft-office.info or https://microsoft-office.app or https://microsoft-office.ninja?
I think people are more worried about TLDs like .zip (and .app) since they look familiar to normal users and they routinely click on those and don't think about them being a valid URL now.
Because of that, as unfair as it is, to this day when I see one of the extended TLDs, I get more suspicious about the site. I tend to avoid them unless I'm very sure they're legit.
NY's transit agency - the MTA - used (and still uses) the domain mta.info. My high school blocked that domain, along with every other info domain.
I have a .xyz domain that I briefly wanted to use for email, but services blocked it based entirely off the TLD. Using the same mail service (fastmail) I could send mail from my .net domains.