The phishing attack occures when you look at the URl before clicking on it.
http://www.microsoft.com:getwindowsforyourcomputer.etc@evils... looks safe for civilians.
<a href="http://evilsite.com">microsoft.com</a> ?