I just ran this grep -rlw "domain.com" /* --exclude-dir={proc,tmp,mnt,bin,boot,opt,snap,srv,sys,run} instead so as to only print the filenames.
/root/.local/share/nano/search_history
/root/allDB.sql
/root/.acme.sh/domain.com_ecc/domain.com.conf
/root/.acme.sh/domain.com_ecc/domain.com.csr.conf
/root/.bash_history
/usr/local/lscp/cyberpanel/logs/access.log
/usr/local/lsws/logs/access.log
/usr/local/lsws/logs/access.log.2022_06_04
/usr/local/lsws/conf/httpd_config.conf0,v
/usr/local/maldetect/logs/event_log
/var/lib/redis/dump.rdb
/var/lib/mysql/mysqld-bin.000083
/var/lib/mysql/mysqld-bin.000091
/var/lib/mysql/mysqld-bin.000039
/var/lib/mysql/mysqld-bin.000024
/var/lib/mysql/mysqld-bin.000013
/var/lib/mysql/mysqld-bin.000020
/var/lib/mysql/mysqld-bin.000028
/var/lib/mysql/mysqld-bin.000037
/var/lib/mysql/mysqld-bin.000119
/var/lib/mysql/mysqld-bin.000069
/var/lib/mysql/mysqld-bin.000023
/var/lib/mysql/ib_logfile0
/var/lib/mysql/mysqld-bin.000042
/var/lib/mysql/mysqld-bin.000035
/var/lib/mysql/mysqld-bin.000098
/var/lib/mysql/mysqld-bin.000097
/var/lib/mysql/mysqld-bin.000034
/var/lib/mysql/mysqld-bin.000087
/var/lib/mysql/mysqld-bin.000086
/var/lib/mysql/mysqld-bin.000124
/var/lib/mysql/mysqld-bin.000147
/var/lib/mysql/mysqld-bin.000002
/var/lib/mysql/mysqld-bin.000111
/var/lib/mysql/mysqld-bin.000041
/var/lib/mysql/mysqld-bin.000170
/var/lib/mysql/mysqld-bin.000025
/var/lib/mysql/mysqld-bin.000125
/var/lib/mysql/mysqld-bin.000167
/var/lib/mysql/ibdata1
/var/lib/mysql/mysqld-bin.000036
/var/lib/mysql/mysqld-bin.000132
/var/lib/mysql/mysqld-bin.000143
/var/lib/lsphp/session/lsphp73/sess_qatb9smvb83rjcivocsh0h69dk
/var/lib/lsphp/session/lsphp73/sess_kd99cknn890it0809tqmai46hs
/var/log/sudo-io/00/04/6M/ttyin
/var/log/sudo-io/00/04/6M/ttyout
/var/log/sudo-io/00/04/7L/ttyin
/var/log/sudo-io/00/04/7L/ttyout
/var/log/sudo-io/00/04/7U/ttyin
/var/log/sudo-io/00/04/7U/ttyout
/var/log/sudo-io/00/04/7O/stdout
/var/log/sudo-io/00/04/84/ttyout
/var/log/sudo-io/00/04/1D/ttyout
/var/log/sudo-io/00/02/U6/ttyout
/var/log/sudo-io/00/02/VZ/ttyout
/var/log/sudo-io/00/00/4Z/ttyout
/var/log/sudo-io/00/03/I2/ttyout
/var/log/lynis.log
/var/log/lynis-report.dat
They mostly seem tobe log files. This one seems most suspicious/promising /usr/local/lsws/conf/httpd_config.conf0,v
I see the domain many times there, but not sure what is really happening in it. There’s also plenty of other previously-used domains listed in that file that are not having this problem