Current File : /home/tdmfgi5/.imh/str_2017-03-08_08:43:07 |
>>> /opt/sharedrads/check_user tdmfgi5 --plaintext
#################################################################################
INMOTION HOSTING .:: SHARED RADS ::. SHARED RESOURCE ABUSE DETECTION SCRIPTS
#################################################################################
Wed Mar 8 08:43:02 EST 2017
Displaying today's most recent CPU usage data as recorded by process accounting
CPU minutes: 223.56cp (7.88%) Actual time: 607.65re (0.10%)
(since my last data poll @ 06:07 EST tdmfgi5 burned another ~94 cp)
# of executions for CPU intensive processes that have been spawned by this user today
php: 1758 perl: 0 imap: 38 pop3: 0 exim: 144 boxtrap: 0 ftp: 0 cron: 0
CPU minutes used today Historical CPU usage data Most expensive processes
12:00AM EST :: 0.04cp Mar 07 :: 350.84cp (4.32%) php-cgi :: 28.36 secs
03:00AM EST :: 42.1cp Mar 06 :: 352.72cp (3.57%) php-cgi :: 27.59 secs
06:00AM EST :: 129.cp Mar 05 :: 376.68cp (4.22%) php-cgi :: 27.35 secs
(no data available) Mar 04 :: 332.83cp (4.22%) php-cgi :: 26.92 secs
(no data available) Mar 03 :: 341.22cp (4.24%) php-cgi :: 26.86 secs
(no data available) Mar 02 :: 292.01cp (3.46%) php-cgi :: 26.83 secs
(no data available) Mar 01 :: 310.45cp (3.80%) php-cgi :: 26.60 secs
(no data available) Feb 28 :: 286.94cp (3.30%) php-cgi :: 26.58 secs
Displaying top utilization processes for user as recorded by cPanel and dcpumon
Top Process %CPU 102 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
Top Process %CPU 99.4 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
Top Process %CPU 97.9 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
RADS has detected these custom cron jobs currently enabled for this account
SHELL="/bin/bash"
* * * * * cd /home/tdmfgi5/public_html; php /home/tdmfgi5/public_html/cron.php > /dev/null
2 23 * * 0 /usr/local/bin/imap-archiver -p -q
USER QUERIES TIME LOCKTIME ROWSSENT ROWSRECVD
tdmfgi5 15 49 0 3 12
ERROR: Could not locate any bandwidth data for tdmfgi5 in /var/cpanel/bandwidth/
>>> /opt/sharedrads/nlp tdmfgi5 -p -w 80 --today
Using /usr/local/apache/domlogs/tdmfgi5/pur-tungsten.tdmfginc.com
[1;35m-Hourly hits (08/Mar/2017)------------------------------------------------------[0m
07: 219 08: 152
[1;35m-HTTP response codes------------------------------------------------------------[0m
200: 349 301: 11 302: 6 404: 5
[1;35m-Duplicate requests + response codes--------------------------------------------[0m
266 200 GET /2015/11/02/hello-world/
29 200 GET /2014/07/06/audio-post-format/
8 301 GET /index.php/component/users/?view=registration
6 200 GET /product/pur-tungsten-ice-fishing-jigs/
4 200 GET /product/black-belt/
4 200 GET /product/glitterglam-belt/
4 200 GET /product/maxi-belt/
4 200 GET /product/pur-tungsten-jigging-spoon/
4 200 POST /wp-comments-post.php
4 302 POST /wp-comments-post.php
[1;35m-Requests for non-static content------------------------------------------------[0m
266 200 GET /2015/11/02/hello-world/
29 200 GET /2014/07/06/audio-post-format/
8 301 GET /index.php/component/users/
6 200 GET /product/pur-tungsten-ice-fishing-jigs/
4 200 GET /product/black-belt/
4 200 GET /product/glitterglam-belt/
4 200 GET /product/maxi-belt/
4 200 GET /product/pur-tungsten-jigging-spoon/
4 200 POST /wp-comments-post.php
4 302 POST /wp-comments-post.php
[1;35m-Top user agents----------------------------------------------------------------[0m
295 "Mozilla/5.0 (Windows NT 6.2; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0"
15 "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; en) Opera 8.50"
9 "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0"
9 "Opera/9.80 (Windows NT 6.2; Win64; x64) Presto/2.12.388 Version/12.17"
6 "Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.
6 "Mozilla/5.0 (Windows NT 6.1; rv:43.0) Gecko/20100101 Firefox/43.0"
5 "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
5 "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko
3 "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrom
3 "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko
[1;35m-Top IPs with PTR records-------------------------------------------------------[0m
57 101.109.129.56 node-piw.pool-101-109.dynamic.totbb.net.
32 101.109.184.88 node-10ew.pool-101-109.dynamic.totbb.net.
19 1.1.189.139 node-c5n.pool-1-1.dynamic.totbb.net.
17 101.109.133.39 node-qav.pool-101-109.dynamic.totbb.net.
17 125.25.34.52 node-6r8.pool-125-25.dynamic.totbb.net.
13 46.161.9.22 No Record Found
8 101.109.39.107 node-7sb.pool-101-109.dynamic.totbb.net.
8 107.174.227.249 107-174-227-249-host.colocrossing.com.
8 118.172.183.98 node-1082.pool-118-172.dynamic.totbb.net.
7 5.188.211.170 Resolver Error
>>> /opt/sharedrads/recent-cp tdmfgi5 -b
[2K+---------+------------------+------------------+------------------+------------------+
| command | 1m | [4m5m[0m | 15m | 60m |
+---------+------------------+------------------+------------------+------------------+
| pyzor | 0.00s 0.0% | 0.00s 0.0% | 0.16s 0.0% | 0.99s 0.1% |
| exim | 0.00s 0.0% | 0.00s 0.0% | 0.02s 0.0% | 0.08s 0.0% |
| bash | 0.00s 1.6% | 0.01s 0.0% | 0.02s 0.0% | 0.16s 0.0% |
| imap | 0.00s 0.0% | 0.13s 0.1% | 0.43s 0.1% | 0.82s 0.0% |
| pop3 | 0.00s 0.0% | 0.36s 0.2% | 0.56s 0.1% | 0.73s 0.0% |
| php | 0.06s 98.4% | 0.37s 0.2% | 1.14s 0.3% | 4.24s 0.2% |
| php-cgi | 0.00s 0.0% | 155.90s 99.4% | 442.99s 99.5% | 1831.43s 99.6% |
+---------+------------------+------------------+------------------+------------------+
| total | 0.06s 100.0% | 156.77s 100.0% | 445.31s 100.0% | 1838.45s 100.0% |
+---------+------------------+------------------+------------------+------------------+
s = processs user time in cpu seconds, cp = user time + system time in cpu minutes
>>> Running processes prior to suspension
USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
tdmfgi5 328035 0.0 0.0 34976 3552 ? S 08:17 0:00 dovecot/imap
tdmfgi5 393588 0.0 0.0 34700 3244 ? S 08:34 0:00 dovecot/imap
tdmfgi5 393728 0.0 0.0 51032 9948 ? S 08:34 0:00 dovecot/pop3
tdmfgi5 417285 0.0 0.0 34592 3156 ? S 08:39 0:00 dovecot/imap
tdmfgi5 428258 0.0 0.0 34536 2688 ? S 08:42 0:00 dovecot/imap
tdmfgi5 428260 0.1 0.0 35004 3636 ? S 08:42 0:00 dovecot/imap
tdmfgi5 428887 0.0 0.0 34536 2684 ? S 08:42 0:00 dovecot/imap