http://news.poseidon-us.com/TJ3gSW
While hunting, I spent some time trying to deobfuscate a malicious file discovered on VT. It triggered my PowerShell rule. At the end, I found two files that look close together:
http://news.poseidon-us.com/TJ3gSW
http://news.poseidon-us.com/TJ3gSW