Description: Malicious tracking code added to the page to notify attackers that a backdoor is present on that page.
Domains used (,,, etc):
<img heigth="1" width="1" border="0" src=""
<img width=0 height=0 src=""
Affecting: Any web site (generally WordPress sites)
Clean up: The malicious code has to be removed, as well as all backdoors. Contact sucuri for help.
Malware dump:
<img width=0 height=0 src=""