EDIT: There is definitely a mismatch between the display URL and the landing page URL. It's not clear to me how that can happen; for example https://www.youtube.com/watch?v=jx-gl6K2zQw shows that only the display path can be edited (not the domain), consistently with the wording on https://support.google.com/google-ads/answer/2616010 and https://support.google.com/google-ads/answer/2375287 . On the other hand, https:…
I can't get the ad to show up for me, but maybe GIMP has an open redirect on their website and the malvertiser is taking advantage of that?
The scam ad says "gimp.org" but if you follow it, the landing page is hosted at gimp.monster. It's a clone of the proper gimp.org with a the download instead pointing to who-knows-what .exe on Dropbox.
WHOIS gimp.monster has WHOIS-guard, but the Icelandic "privacy" address turns up a bunch of Reddit links about scam sites. Namecheap is the common thread, but that's hardly a lead.