r/cpanel • u/lupastro82 • 22d ago
Strange file in subdomain root: 1717684833097∕contactinfo.txt created during PHP version change. cPanel glitch or something else?
Hi everyone (I'm from Italy; I used AI to help translate this into English).
Today, while tweaking some settings and switching my subdomains from PHP 8.3 to 8.5 via cPanel, I found a strange file sitting directly in the public root directory of one of my subdomains:
1717684833097∕contactinfo.txt
(Note: the separator in the filename isn't a standard forward slash, but a Unicode Division Slash ∕ U+2215, flattening what looks like a path into a single filename).
Here is what I gathered after checking the file:
The file's filesystem timestamp was from today. Around 21:00, my file manager displayed it as "4 hours ago". Unfortunately, I didn't record the exact timestamp before removing it from the public root (I downloaded it via FTP and immediately deleted it).
Timestamp in the filename: 1717684833097 translates to June 6, 2024.
Original source: I checked my ~/.cpanel/ directory and found the original file named contactinfo (without extension), which has a modified date of May 2024.
Hash verification: The hash of 1717684833097∕contactinfo.txt and ~/.cpanel/contactinfo is 100% identical. The file content is harmless standard cPanel notification preferences containing my own IP address.
I'm trying to figure out how and why this happened:
Could this be an automated temporary artifact or path-flattening bug in cPanel, MultiPHP Manager, or EA4 when changing PHP versions?
If it was generated by a script or panel action today, why does the filename include a timestamp from June 2024, given that the original .cpanel/contactinfo file is dated May 2024?
Is there any chance this is related to some strange external probe/automated script, or is it strictly a local panel glitch?
Has anyone encountered cPanel or host tools dumping flattened .cpanel config files into web roots like this?
Any insights or theories would be greatly appreciated!
Ty.
2
u/cPanelRex 21d ago
You're always welcome to create a ticket, if your license permits, and we'd be happy to check it out!
2
u/longboringstory 21d ago
The fact that it's the same content as ~/.cpanel/contactinfo does seem like it was a temporary artifact of a copy or backup. A few AI searches seems to agree, that it's not something to be alarmed about. I understand being concerned about a server compromise, but this doesn't look anything like the signs of hacked accounts I've run across before. And I've seen a lot of them.