Defacement on website with hidden iFrame not flagged by AOS?

See: http://killmalware.com/my1penang.com/ parser error hack…22 days and up…
Missed: https://www.virustotal.com/en/url/077c4450072aa591cc6868a9c8216407e248ace68a4c1031a792465cd6119fe3/analysis/
Alerted: Web site defaced. Details: http://sucuri.net/malware/entry/MW:DEFACED:01

Hacked By CoMoDo ! Unified Layer Host Monster abuse (once also infested with Zeus) IP: https://www.virustotal.com/en/ip-address/74.220.202.45/information/ Host Monster says there is no website configured at this address. Bad web rep: https://www.mywot.com/en/scorecard/74.220.202.45?utm_source=addon&utm_content=warn-viewsc Tracking IDs could be sent safely if this site was secure. Tracking IDs do not support secure transmission. Re: http://toolbar.netcraft.com/site_report?url=http://74.220.202.45 Lately detected Trojan.Agent.rfz (npt by Avast's). Read also: http://bl.ocks.org/GerHobbelt/2623079

polonus