Current File : /home/tdmfgi5/.imh/str_2017-10-05_13:43:11 |
>>> /opt/sharedrads/check_user tdmfgi5 --plaintext
#################################################################################
INMOTION HOSTING .:: SHARED RADS ::. SHARED RESOURCE ABUSE DETECTION SCRIPTS
#################################################################################
Thu Oct 5 13:43:03 EDT 2017
Displaying today's most recent CPU usage data as recorded by process accounting
CPU minutes: 320.87cp (8.18%) Actual time: 4844.22re (0.39%)
(since my last data poll @ 12:07 EDT tdmfgi5 burned another ~48 cp)
# of executions for CPU intensive processes that have been spawned by this user today
php: 2757 perl: 0 imap: 816 pop3: 0 exim: 452 boxtrap: 0 ftp: 0 cron: 0
CPU minutes used today Historical CPU usage data Most expensive processes
12:00AM EDT :: 0.67cp Oct 04 :: 417.43cp (6.96%) php-cgi :: 107.29 secs
03:00AM EDT :: 52.9cp Oct 03 :: 502.37cp (8.48%) php-cgi :: 29.95 secs
06:00AM EDT :: 127.cp Oct 02 :: 509.76cp (8.32%) php-cgi :: 29.54 secs
09:00AM EDT :: 198.cp Oct 01 :: 516.98cp (8.94%) php-cgi :: 29.11 secs
12:00PM EDT :: 272.cp Sep 30 :: 566.88cp (10.74%) php-cgi :: 28.54 secs
(no data available) Sep 29 :: 606.30cp (9.92%) php-cgi :: 27.61 secs
(no data available) Sep 28 :: 640.34cp (9.48%) php-cgi :: 27.46 secs
(no data available) Sep 27 :: 661.26cp (10.66%) php-cgi :: 27.31 secs
Displaying top utilization processes for user as recorded by cPanel and dcpumon
Top Process %CPU 113 /bin/bash -c cd /home/tdmfgi5/public_html; php /home/tdmfgi5/public_html/cron.php > /dev/null
Top Process %CPU 112 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
Top Process %CPU 107 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
RADS has detected these custom cron jobs currently enabled for this account
SHELL="/bin/bash"
* * * * * cd /home/tdmfgi5/public_html; php /home/tdmfgi5/public_html/cron.php > /dev/null
2 23 * * 0 /usr/local/bin/imap-archiver -p -q
USER QUERIES TIME LOCKTIME ROWSSENT ROWSRECVD
tdmfgi5 1 3 0 0 0
ERROR: Could not locate any bandwidth data for tdmfgi5 in /var/cpanel/bandwidth/
>>> /opt/sharedrads/nlp tdmfgi5 -p -w 80 --today
Using /var/log/apache2/domlogs/tdmfgi5/tdmfginc.com
[1;35m-Hourly hits (05/Oct/2017)------------------------------------------------------[0m
08: 71 09: 190 10: 59 11: 459 12: 592 13: 278
[1;35m-HTTP response codes------------------------------------------------------------[0m
200: 1584 301: 18 302: 15 304: 3 404: 26 503: 3
[1;35m-Duplicate requests + response codes--------------------------------------------[0m
305 200 POST /wp-admin/admin-ajax.php
30 200 GET /favicon.ico
27 200 GET /
19 200 GET /robots.txt
18 200 GET /wp-content/plugins/revslider/public/assets/js/extensions/revolu
18 200 GET /wp-content/plugins/revslider/public/assets/js/extensions/revolu
17 200 GET /wp-content/uploads/2017/04/Group-1.png
17 200 GET /wp-includes/js/jquery/jquery.js?ver=1.12.4
17 200 GET /wp-includes/js/wp-emoji-release.min.js?ver=4.7.6
16 200 GET /wp-content/cache/autoptimize/css/autoptimize_2d0098c9224ef4d4d4
[1;35m-Requests for non-static content------------------------------------------------[0m
305 200 POST /wp-admin/admin-ajax.php
42 200 GET /
21 200 POST /wp-cron.php
15 200 GET /wp-content/themes/betheme/fonts/mfn-icons.woff
14 200 GET /portfolio-item/tungsten-carbide-end-mills
14 404 GET /
11 200 GET /wp-admin/post.php
11 302 POST /wp-admin/post.php
10 200 GET /products
9 301 GET /
[1;35m-Top user agents----------------------------------------------------------------[0m
1020 "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Geck
107 "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko"
64 "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/53
61 "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/53
54 "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
51 "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko"
50 "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chro
43 "Mozilla/5.0 (iPhone; CPU iPhone OS 11_0_2 like Mac OS X) AppleWebKit/604
27 "WordPress/4.7.6; http://tdmfginc.com"
25 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik
[1;35m-Top IPs with PTR records-------------------------------------------------------[0m
1045 69.249.56.194 c-69-249-56-194.hsd1.pa.comcast.net.
93 66.249.70.9 crawl-66-249-70-9.googlebot.com.
57 50.225.175.194 No Record Found
52 75.75.223.242 No Record Found
51 76.76.56.225 cpe-76-76-56-225.popp.net.
50 45.249.165.252 node-45-249-165-252.alliancebroadband.in.
43 66.216.240.111 66-216-240-111.dhcp.stcd.mn.charter.com.
33 66.102.8.41 google-proxy-66-102-8-41.google.com.
27 144.208.76.152 ecld208.inmotionhosting.com.
25 66.102.8.43 google-proxy-66-102-8-43.google.com.
>>> /opt/sharedrads/recent-cp tdmfgi5 -b
[2K+-------------+------------------+------------------+------------------+------------------+
| command | 1m | [4m5m[0m | 15m | 60m |
+-------------+------------------+------------------+------------------+------------------+
| dovecot-lda | 0.00s 0.0% | 0.00s 0.0% | 0.01s 0.0% | 0.01s 0.0% |
| exim | 0.00s 0.0% | 0.00s 0.0% | 0.06s 0.0% | 0.10s 0.0% |
| pop3 | 0.00s 0.0% | 0.01s 0.0% | 0.35s 0.1% | 0.39s 0.0% |
| imap | 0.00s 0.0% | 0.07s 0.1% | 0.31s 0.1% | 1.76s 0.1% |
| pyzor | 0.00s 0.0% | 0.08s 0.1% | 0.56s 0.1% | 1.46s 0.1% |
| php | 0.05s 7.5% | 0.27s 0.2% | 0.80s 0.2% | 3.35s 0.2% |
| bash | 0.62s 92.5% | 2.66s 2.3% | 5.82s 1.2% | 27.26s 1.5% |
| php-cgi | 0.00s 0.0% | 112.94s 97.3% | 465.27s 98.3% | 1737.43s 98.1% |
+-------------+------------------+------------------+------------------+------------------+
| total | 0.67s 100.0% | 116.03s 100.0% | 473.18s 100.0% | 1771.75s 100.0% |
+-------------+------------------+------------------+------------------+------------------+
s = processs user time in cpu seconds, cp = user time + system time in cpu minutes
>>> Running processes prior to suspension
USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
tdmfgi5 14078 0.0 0.0 86728 5616 ? S 08:48 0:00 dovecot/imap
tdmfgi5 33806 0.0 0.0 86348 5212 ? S 10:37 0:00 dovecot/imap
tdmfgi5 73173 0.0 0.0 86856 5464 ? S 11:38 0:00 dovecot/imap
tdmfgi5 86133 0.0 0.0 86228 4688 ? S 13:28 0:00 dovecot/imap
tdmfgi5 86157 0.0 0.0 85888 4336 ? S 13:28 0:00 dovecot/imap
tdmfgi5 88356 0.0 0.0 86688 5324 ? S 13:28 0:00 dovecot/imap
tdmfgi5 88659 0.0 0.0 86872 5440 ? S 13:28 0:00 dovecot/imap
tdmfgi5 134639 0.0 0.0 86300 5152 ? S 13:40 0:00 dovecot/imap