http://5cjzn74dpcafedj4dngccvyvtmo7bgtmzibyurfc7lkff6q7ep4quwad.onion/horabot-botnet-malware-targets-users-in-latin-america
The onset of the attacks commences with the dissemination of phishing emails that bear tax-themed attachments, aimed at inducing the recipients to open an HTML attachment. This attachment, in turn, embeds a link that contains a RAR archive. Upon opening the contents of the file, a PowerShell downloader script is executed, which is responsible for retrieving a ZIP file containing the primary payloads from a remote server and initiating a system restart.