system
5
The point of my post is you should realize that Sucuri SiteCheck treats all sites it scans as legitimate sites that might be compromised. So it only looks for patterns that show that there may be something that webmasters didn’t mean to have on their sites.
Outright malicious sites (created specifically to distribute malware) are usually different beasts and normal patterns are not applicable to them. SiteCheck can only flag them if it finds malware that can also be found on infected site or the domains are blacklisted by some of our partners.
In this case, the domain name looks pretty random, which means there may be lots of them used by this attack and each of them is only active during a very limited period of time. So just finding and blacklisting such domains is not a good strategy for Sucuri. It would be more beneficial to see if these domains are used in site infections and detect the malicious code they are associated with. So if you have this additional information (at least a live infected site) we’d love to hear from you 