Notes on the Spam Hack
Yes — and there is still evidence of SEO spam/hacked content bleeding into parts of the site.
These pages are infected or contaminated with spam injections:
Resources Page (infected)
AuD Externship Sites (infected)
The injected content includes:
“PRAGMATIC PLAY”
“slot gacor”
“OMACUAN”
gambling/spam keywords
That means:
either the database still contains injected content,
or a theme/plugin/template file is still compromised.
But:
the sitemap itself appears readable,
and many normal pages still render correctly.
Next steps:
Reinstall the active theme completely.
Delete ALL unused themes.
Empty plugins folder again except trusted plugins.
Search database/content for:
OMACUAN
slot gacor
PRAGMATIC PLAY
slot777
Check:
wp-content/themes
for:
header.php
footer.php
functions.php
single.php
archive.php
Re-save permalinks in WordPress.
Regenerate sitemap with a trusted SEO plugin only after cleanup.
The infection is no longer root-level obvious, but the site is still partially contaminated.
This page, https://audclinicaled.net/?s=slot+gacor&tcb_sf_post_type%5B%5D=post&tcb_sf_post_type%5B%5D=page, turns up positive for a search for "slot gacor" but I can not find any instances of "slot gacor" in the page or template.
That strongly suggests one of these:
Hidden database spam
Conditional malware output
Cached spam page
Search index poisoning
Thrive Theme search indexing contamination
Most likely:
the malware inserted hidden posts/pages/options into the database.
Check these areas inside WordPress database:
wp_posts
wp_options
wp_postmeta
Search database for:
slot gacor
OMACUAN
PRAGMATIC PLAY
Especially inspect:
drafts
trashed posts
revisions
hidden pages
Thrive templates
Thrive Architect content
Also check:
/wp-content/cache
/wp-content/uploads
for generated cached HTML.
Another important clue:
Your URL is a SEARCH URL:
?s=slot+gacor
WordPress search pages can:
echo the search term,
or surface hidden indexed spam content.
So the infection may no longer be active, but the database/search index still contains polluted content.
Also clear:
WP Rocket cache
object cache
CDN cache if any
Google indexed cache takes longer.
https://search.google.com/test/rich-results?utm_source=chatgpt.com

The Internet Janitor Shift Nobody Talks About
Instead of building new projects this week, I spent my days dragging malware, spam injections, broken plugins, and bloated WordPress debris out of the digital gutters.
This week disappeared into the digital mud.
- Not building.
- Not coaching.
- Not creating.
- Not publishing.
Just chasing malware ghosts through WordPress installations like some exhausted night janitor cleaning up after internet vandals.
- FTP crawls.
- WordFence scans drag for hours.
- Database tables bloat like abandoned storage lockers.
- Plugins fight each other.
- Caches regenerate junk.
- SEO spam leaves fingerprints in places no human would ever intentionally build.
And every hour spent cleaning infected files is an hour NOT spent making something useful.
The modern web stack has become absurdly fragile. One outdated plugin, one forgotten staging site, one bad password, one neglected cache system — and suddenly you’re pulling hacker debris out of server directories instead of moving projects forward.
The frustrating part is not even the attack itself. It is the endless cleanup theater afterward:
- reinstalls,
- permission resets,
- database inspections,
- false positives,
- real positives,
- Google warnings,
- AMP weirdness,
- mystery cron jobs,
- half-broken plugins, and
- enough cache layers to make a grown adult question every life decision that led to self-hosted WordPress.
The belt buckle is tightening.
- Fewer plugins.
- Fewer moving parts.
- Fewer bloated systems.
- More streamlined publishing.
- More durable platforms.
- Less dependency on fragile software towers stacked on top of each other like wet cardboard.
The internet used to feel open and creative.
Now half the work is digital sanitation.
- Still moving forward.
- Still rebuilding.
- Still publishing.
But the tolerance for unnecessary complexity is rapidly approaching zero.
Punchlist
May 2026 Recovery / Hardening / Cleanup Operations
This document summarizes the major malware discoveries, cleanup actions, stabilization work, cache removals, plugin reductions, and operational decisions made across the WordPress ecosystem.
SITE: audclinicaled.net
Confirmed Problems
SEO Spam Injection
Google Search Console showed:
- “slot gacor”
- “OMACUAN”
- “PRAGMATIC PLAY”
- Indonesian gambling spam
- fake product schema injections
Spam references included:
- imgmahasuhu.io
- Slot777
- Slot88
- fake merchant product markup
Cleanup Actions
Rank Math Removed
- Rank Math plugin fully removed/nuked
- old Rank Math tables identified
- sitemap strategy changed to native WordPress sitemap
WP Rocket Removed
- WP Rocket disabled/removed
- stale cache systems targeted for deletion
Thrive Theme Reinstall
- Thrive Theme Builder fully deleted/reinstalled
- Thrive plugins reviewed for integrity
WordFence Review
- WAF reviewed
- scans repeatedly run
- suspicious files inspected manually
Suspicious Core Path Cleanup
Inspected and/or removed suspicious paths including:
- wp-admin/network/w3tc-config
- wp-includes/.../maint
- wp-includes/.../themes
- wp-includes/.../html-api
- wp-includes/.../wflogs
Database Inspection
- wp_postmeta identified as extremely large
- Better Search Replace used
- SEO spam search terms investigated
- “slot gacor” searches eventually returned clean
Uploads Directory Review
Reviewed:
- Thrive template folders
- NinjaForms uploads
- old cache remnants
Cache/System Reduction
Targeted removal of:
- W3 Total Cache remnants
- WP Rocket remnants
- old cache folders
AMP Removal Decision
Decision made to:
- fully remove AMP ecosystem-wide
SITE: jobs.swimisca.org
Confirmed Malware
Infected index.php
Confirmed malicious injected code:
- fake Googlebot detection
- seoikan parameter
- remote payload loading
- oma.haxor-mahasuhu.info
Behavior:
- served hidden SEO spam to crawlers
- cloaked content from normal users
Sitemap Concerns
Potentially malicious/custom sitemap.xml identified.
Suspicious mu-plugins Structure
Found:
- empty nested plugins folder under mu-plugins
- removed as unnecessary/suspicious
Cleanup Actions
index.php Replaced
Malicious index.php removed and replaced with:
- clean WordPress core version
Cache Cleanup
Removed/targeted:
- WP Rocket cache
- wp-content/cache
- advanced-cache.php
- object-cache.php
Plugin Isolation
- plugins directory emptied
- temporary plugin isolation testing performed
Theme Isolation
- fallback/default theme testing planned
Database Recovery
- database instability later linked to Pair.com InnoDB corruption/restoration event
DB_HOST Troubleshooting
Tested:
- localhost
- vqs3387.pair.com
.user.ini Review
Reviewed possible:
- auto_prepend_file issues
- WordFence WAF references
SITE: read.swimisca.org
Confirmed Malware
KINGSMAN Malware Directory
Confirmed malicious directory:
- /wp-content/KINGSMAN/
Contained:
- bash.haxor
- perl.haxor
- py.haxor
This represented one of the clearest confirmed malware payloads discovered.
Cleanup Actions
KINGSMAN Removed
Entire malicious directory deleted.
php-errors Review
Log analysis showed:
- WP Rocket timeout issues
- Thrive Comments missing file issues
- LearnDash warnings
- Rank Math remnants
- database stress/timeouts
Cache Reduction
Planned:
- WP Rocket removal
- cache simplification
Staging Directory Review
- old staging structure reviewed
- concern raised over outdated staging environments
Plugin Simplification
Goal established:
- reduce plugin complexity
- reduce abandoned systems
SITE: isca.blue
Confirmed Problems
WordFence Core Alerts
Detected:
- modified core index.php
- multiple fake WordPress core directories
Included:
- wp-admin/network/w3tc-config
- wp-includes/.../maint
- wp-includes/.../busting
- wp-includes/.../themes
- wp-includes/.../wflogs
AMP Issues
Google Search Console reported AMP problems.
Cleanup Actions
WordPress Core Reinstall
Recommended/performed:
- WordPress core reinstall
Fake Core Directory Cleanup
Suspicious directories identified for deletion.
AMP Shutdown Strategy
Decision:
- fully disable/remove AMP
W3TC Removal
Reviewed/removing:
- wp-content/w3tc-config
- legacy cache remnants
Cache Folder Cleanup
Reviewed:
- wp-content/cache
- critical-css
- wp-rocket
- min
- background-css
SITE: help.cloh.org
Confirmed Malware Indicators
Suspicious sodium_compat Activity
WordFence flagged:
- modified Precomp.php
- unknown file: fuu4-1.php
Rogue .htaccess
Found suspicious .htaccess inside:
- sodium_compat cryptography directories
Included:
- “Require all granted”
- PHP execution permissions
Cleanup Actions
Core Repair
- WordFence repair recommended/performed
Malware File Removal
- fuu4-1.php removed or disappeared after repair/reinstall
Rogue .htaccess Removal
- suspicious .htaccess targeted for deletion
WordPress Core Verification
Confirmed legitimate cryptography files:
- Cached.php
- P1p1.php
- P2.php
- P3.php
- Precomp.php
SERVER-WIDE ACTIONS
Pair.com Database Recovery Event
Pair.com later confirmed:
- MySQL/InnoDB corruption
- services restored from May 10 backup snapshot
- database instability contributed to site failures
This explained:
- intermittent DB errors
- failed password changes
- unstable behavior
- inconsistent WordPress operation
SECURITY HARDENING ACTIONS
Permissions Standardization
Directories:
- 755
Files:
- 644
Discussed:
- wp-config.php potentially hardened to 640
Plugin Reduction Strategy
Decision:
- aggressively reduce plugin count
- remove abandoned systems
- simplify WordPress architecture
Cache Reduction Strategy
Targeted removal:
- WP Rocket
- W3 Total Cache remnants
- stale cache folders
- advanced-cache.php
- object-cache.php
AMP Elimination Strategy
Decision:
- remove AMP from ecosystem
Reasons:
- complexity
- Thrive conflicts
- indexing confusion
- unnecessary attack surface
Source: helpdesk.WordPress.2026-06-05.xml · Original ID: 4886