Thank you for your input. I did change hosting server in the meantime and got again the redirect on my site with DNS being hijacked as well. Also scanreport from server is clean and wordfence and sucuri scans are clean.
My main suspicion now has to do with an oversized file that couldn’t be scanned through your plugin, wp/content/ So I’m trying to run the plugin with the oversize setting you mentioned or get this file analysed through another tool.