This is known as a conditional payload, we actually just wrote a post about what that is on our blog:
http://blog.sucuri.net/2014/09/conditional-malicious-iframe-targeting-wordpress-web-sites.html
and explain it again in an older post here:
http://blog.sucuri.net/2012/06/understanding-conditional-malware-ip-centric-variation.html
Thanks