Ha, easy! You simply have to compare the angle of the slashes to the ones after https: obviously in the first link the angle is too flat which indicates that it is a special character and no slash. So this is the link more likely containing the malware. As I said: Really obvious!
... we'll be fine.
@hanser @ariadne
or you just mouseover the URL and look at the tooltip inthe bottom left corner....