Server Spring Clean-up Continues -- and the source might have been discovered
- Change all remaining passwords:
FTP/SFTP
WordPress admins
database users
Google accounts
- Enable 2FA everywhere possible:
Pair
WordPress
Bitwarden
- Verify Google Search Console:
- remove unknown owners
- remove rogue verification methods
- inspect sitemap submissions
- inspect indexed spam pages
- Verify no rogue FTP users or cron jobs exist.
- Delete:
.tmb
old cache directories
plugins-off leftovers no longer needed
- Keep only clean themes/plugins active.
- Reinstall plugins/themes ONLY from official clean sources.
- Replace wp-admin and wp-includes on every infected site.
- Leave Wordfence active on all sites.
- Run fresh Wordfence scans after each major cleanup step.
- Make fresh CLEAN backups after scans pass.
- Inspect:
.user.ini
wp-config.php
on every site.
- Disable comments globally if not needed.
- Remove unused plugins and themes permanently.
- Reduce writable directories and avoid 777 permissions.
- Clear old debug logs and monitor for NEW entries only.
- Keep sites lightweight until stability is proven.
- Search ALL sites and home directories for these strings:
avatar-amp
seoikan
haxor
mahasuhu
sys_waf_bypass_fetch
_compileExecPayloadTask
_compileFetchCoreLite
_compilePushToDiskNode
MY LAST DANCE
Tennessee
Backup-Shell
logger.txt
watchdogd
defunct
base64 -d|bash
eval(
base64_decode
google-site-verification
- Search for suspicious filenames:
48r.php
de.php
big.php
12.php
pipe.php
framework.php
pluginloader.php
archive.php
filestore.php
nui1.php
nui1-1.php
nui1-2.php
nui1-3.php
gej3.php
gej3-1.php
gej3-2.php
gej3-3.php
importer.php
.™.php
- Search especially inside:
uploads
cache
themes
plugins
cgi-bin
~/.config
~/
Source: helpdesk.WordPress.2026-06-05.xml · Original ID: 4905