Malware generates a pseudo-random domain name, depending on the current date. Malware encrypts all the content of the infected file to hide the malicious code together with the clean one. The malware is not so easy to discover: it doesnt have the specific signature and every infected file will strongly differ from another, because the obfuscated version depends on the clean content. The most similar case is the Gumblar-like Trojan, discovered in 2010, which steals credentials to FTP accounts and infects the HTML/PHP files on the server with the code that contain the gootkit strings.”]
Source: https://securelist.com/runforestrun-gootkit-and-random-domain-name-generation/57865/

