Mark RauterkusTips

Notes on the Spam Hack

2026-05-10 · Status: private · Audiology, Content, Development, Folly

Yes — and there is still evidence of SEO spam/hacked content bleeding into parts of the site.

These pages are infected or contaminated with spam injections:

Resources Page (infected)
AuD Externship Sites (infected)

The injected content includes:

“PRAGMATIC PLAY”
“slot gacor”
“OMACUAN”
gambling/spam keywords

That means:

either the database still contains injected content,
or a theme/plugin/template file is still compromised.

But:

the sitemap itself appears readable,
and many normal pages still render correctly.

Next steps:

Reinstall the active theme completely.
Delete ALL unused themes.
Empty plugins folder again except trusted plugins.
Search database/content for:
OMACUAN
slot gacor
PRAGMATIC PLAY
slot777
Check:
wp-content/themes

for:

header.php
footer.php
functions.php
single.php
archive.php
Re-save permalinks in WordPress.
Regenerate sitemap with a trusted SEO plugin only after cleanup.

The infection is no longer root-level obvious, but the site is still partially contaminated.

This page, https://audclinicaled.net/?s=slot+gacor&tcb_sf_post_type%5B%5D=post&tcb_sf_post_type%5B%5D=page, turns up positive for a search for "slot gacor" but I can not find any instances of "slot gacor" in the page or template.

That strongly suggests one of these:

Hidden database spam
Conditional malware output
Cached spam page
Search index poisoning
Thrive Theme search indexing contamination

Most likely:
the malware inserted hidden posts/pages/options into the database.

Check these areas inside WordPress database:

wp_posts
wp_options
wp_postmeta

Search database for:

slot gacor
OMACUAN
PRAGMATIC PLAY

Especially inspect:

drafts
trashed posts
revisions
hidden pages
Thrive templates
Thrive Architect content

Also check:

/wp-content/cache
/wp-content/uploads

for generated cached HTML.

Another important clue:
Your URL is a SEARCH URL:

?s=slot+gacor

WordPress search pages can:

echo the search term,
or surface hidden indexed spam content.

So the infection may no longer be active, but the database/search index still contains polluted content.

Also clear:

WP Rocket cache
object cache
CDN cache if any
Google indexed cache takes longer.

https://search.google.com/test/rich-results?utm_source=chatgpt.com

Internet malware

The Internet Janitor Shift Nobody Talks About

Instead of building new projects this week, I spent my days dragging malware, spam injections, broken plugins, and bloated WordPress debris out of the digital gutters.

This week disappeared into the digital mud.

  • Not building.
  • Not coaching.
  • Not creating.
  • Not publishing.

Just chasing malware ghosts through WordPress installations like some exhausted night janitor cleaning up after internet vandals.

  • FTP crawls.
  • WordFence scans drag for hours.
  • Database tables bloat like abandoned storage lockers.
  • Plugins fight each other.
  • Caches regenerate junk.
  • SEO spam leaves fingerprints in places no human would ever intentionally build.

And every hour spent cleaning infected files is an hour NOT spent making something useful.

The modern web stack has become absurdly fragile. One outdated plugin, one forgotten staging site, one bad password, one neglected cache system — and suddenly you’re pulling hacker debris out of server directories instead of moving projects forward.

The frustrating part is not even the attack itself. It is the endless cleanup theater afterward:

  • reinstalls,
  • permission resets,
  • database inspections,
  • false positives,
  • real positives,
  • Google warnings,
  • AMP weirdness,
  • mystery cron jobs,
  • half-broken plugins, and
  • enough cache layers to make a grown adult question every life decision that led to self-hosted WordPress.

The belt buckle is tightening.

  • Fewer plugins.
  • Fewer moving parts.
  • Fewer bloated systems.
  • More streamlined publishing.
  • More durable platforms.
  • Less dependency on fragile software towers stacked on top of each other like wet cardboard.

The internet used to feel open and creative.

Now half the work is digital sanitation.

  • Still moving forward.
  • Still rebuilding.
  • Still publishing.

But the tolerance for unnecessary complexity is rapidly approaching zero.

Punchlist

May 2026 Recovery / Hardening / Cleanup Operations

This document summarizes the major malware discoveries, cleanup actions, stabilization work, cache removals, plugin reductions, and operational decisions made across the WordPress ecosystem.

SITE: audclinicaled.net

Confirmed Problems

SEO Spam Injection

Google Search Console showed:

  • “slot gacor”
  • “OMACUAN”
  • “PRAGMATIC PLAY”
  • Indonesian gambling spam
  • fake product schema injections

Spam references included:

  • imgmahasuhu.io
  • Slot777
  • Slot88
  • fake merchant product markup

Cleanup Actions

Rank Math Removed

  • Rank Math plugin fully removed/nuked
  • old Rank Math tables identified
  • sitemap strategy changed to native WordPress sitemap

WP Rocket Removed

  • WP Rocket disabled/removed
  • stale cache systems targeted for deletion

Thrive Theme Reinstall

  • Thrive Theme Builder fully deleted/reinstalled
  • Thrive plugins reviewed for integrity

WordFence Review

  • WAF reviewed
  • scans repeatedly run
  • suspicious files inspected manually

Suspicious Core Path Cleanup

Inspected and/or removed suspicious paths including:

  • wp-admin/network/w3tc-config
  • wp-includes/.../maint
  • wp-includes/.../themes
  • wp-includes/.../html-api
  • wp-includes/.../wflogs

Database Inspection

  • wp_postmeta identified as extremely large
  • Better Search Replace used
  • SEO spam search terms investigated
  • “slot gacor” searches eventually returned clean

Uploads Directory Review

Reviewed:

  • Thrive template folders
  • NinjaForms uploads
  • old cache remnants

Cache/System Reduction

Targeted removal of:

  • W3 Total Cache remnants
  • WP Rocket remnants
  • old cache folders

AMP Removal Decision

Decision made to:

  • fully remove AMP ecosystem-wide

SITE: jobs.swimisca.org

Confirmed Malware

Infected index.php

Confirmed malicious injected code:

  • fake Googlebot detection
  • seoikan parameter
  • remote payload loading
  • oma.haxor-mahasuhu.info

Behavior:

  • served hidden SEO spam to crawlers
  • cloaked content from normal users

Sitemap Concerns

Potentially malicious/custom sitemap.xml identified.

Suspicious mu-plugins Structure

Found:

  • empty nested plugins folder under mu-plugins
  • removed as unnecessary/suspicious

Cleanup Actions

index.php Replaced

Malicious index.php removed and replaced with:

  • clean WordPress core version

Cache Cleanup

Removed/targeted:

  • WP Rocket cache
  • wp-content/cache
  • advanced-cache.php
  • object-cache.php

Plugin Isolation

  • plugins directory emptied
  • temporary plugin isolation testing performed

Theme Isolation

  • fallback/default theme testing planned

Database Recovery

  • database instability later linked to Pair.com InnoDB corruption/restoration event

DB_HOST Troubleshooting

Tested:

  • localhost
  • vqs3387.pair.com

.user.ini Review

Reviewed possible:

  • auto_prepend_file issues
  • WordFence WAF references

SITE: read.swimisca.org

Confirmed Malware

KINGSMAN Malware Directory

Confirmed malicious directory:

  • /wp-content/KINGSMAN/

Contained:

  • bash.haxor
  • perl.haxor
  • py.haxor

This represented one of the clearest confirmed malware payloads discovered.

Cleanup Actions

KINGSMAN Removed

Entire malicious directory deleted.

php-errors Review

Log analysis showed:

  • WP Rocket timeout issues
  • Thrive Comments missing file issues
  • LearnDash warnings
  • Rank Math remnants
  • database stress/timeouts

Cache Reduction

Planned:

  • WP Rocket removal
  • cache simplification

Staging Directory Review

  • old staging structure reviewed
  • concern raised over outdated staging environments

Plugin Simplification

Goal established:

  • reduce plugin complexity
  • reduce abandoned systems

SITE: isca.blue

Confirmed Problems

WordFence Core Alerts

Detected:

  • modified core index.php
  • multiple fake WordPress core directories

Included:

  • wp-admin/network/w3tc-config
  • wp-includes/.../maint
  • wp-includes/.../busting
  • wp-includes/.../themes
  • wp-includes/.../wflogs

AMP Issues

Google Search Console reported AMP problems.

Cleanup Actions

WordPress Core Reinstall

Recommended/performed:

  • WordPress core reinstall

Fake Core Directory Cleanup

Suspicious directories identified for deletion.

AMP Shutdown Strategy

Decision:

  • fully disable/remove AMP

W3TC Removal

Reviewed/removing:

  • wp-content/w3tc-config
  • legacy cache remnants

Cache Folder Cleanup

Reviewed:

  • wp-content/cache
  • critical-css
  • wp-rocket
  • min
  • background-css

SITE: help.cloh.org

Confirmed Malware Indicators

Suspicious sodium_compat Activity

WordFence flagged:

  • modified Precomp.php
  • unknown file: fuu4-1.php

Rogue .htaccess

Found suspicious .htaccess inside:

  • sodium_compat cryptography directories

Included:

  • “Require all granted”
  • PHP execution permissions

Cleanup Actions

Core Repair

  • WordFence repair recommended/performed

Malware File Removal

  • fuu4-1.php removed or disappeared after repair/reinstall

Rogue .htaccess Removal

  • suspicious .htaccess targeted for deletion

WordPress Core Verification

Confirmed legitimate cryptography files:

  • Cached.php
  • P1p1.php
  • P2.php
  • P3.php
  • Precomp.php

SERVER-WIDE ACTIONS

Pair.com Database Recovery Event

Pair.com later confirmed:

  • MySQL/InnoDB corruption
  • services restored from May 10 backup snapshot
  • database instability contributed to site failures

This explained:

  • intermittent DB errors
  • failed password changes
  • unstable behavior
  • inconsistent WordPress operation

SECURITY HARDENING ACTIONS

Permissions Standardization

Directories:

  • 755

Files:

  • 644

Discussed:

  • wp-config.php potentially hardened to 640

Plugin Reduction Strategy

Decision:

  • aggressively reduce plugin count
  • remove abandoned systems
  • simplify WordPress architecture

Cache Reduction Strategy

Targeted removal:

  • WP Rocket
  • W3 Total Cache remnants
  • stale cache folders
  • advanced-cache.php
  • object-cache.php

AMP Elimination Strategy

Decision:

  • remove AMP from ecosystem

Reasons:

  • complexity
  • Thrive conflicts
  • indexing confusion
  • unnecessary attack surface

Source: helpdesk.WordPress.2026-06-05.xml · Original ID: 4886