Current File : /home/tdmfgi5/.imh/str_2017-11-04_14:43:10 |
>>> /opt/sharedrads/check_user tdmfgi5 --plaintext
#################################################################################
INMOTION HOSTING .:: SHARED RADS ::. SHARED RESOURCE ABUSE DETECTION SCRIPTS
#################################################################################
Sat Nov 4 14:43:02 EDT 2017
Displaying today's most recent CPU usage data as recorded by process accounting
CPU minutes: 540.73cp (12.38%) Actual time: 4046.64re (0.38%)
(since my last data poll @ 12:07 EDT tdmfgi5 burned another ~84 cp)
# of executions for CPU intensive processes that have been spawned by this user today
php: 3295 perl: 0 imap: 148 pop3: 0 exim: 64 boxtrap: 0 ftp: 0 cron: 0
CPU minutes used today Historical CPU usage data Most expensive processes
12:00AM EDT :: 0.69cp Nov 03 :: 612.72cp (9.63%) php-cgi :: 107.56 secs
03:00AM EDT :: 102.cp Nov 02 :: 638.40cp (9.91%) php-cgi :: 30.02 secs
06:00AM EDT :: 220.cp Nov 01 :: 689.13cp (10.41%) php-cgi :: 30.02 secs
09:00AM EDT :: 349.cp Oct 31 :: 767.62cp (11.21%) php-cgi :: 30.01 secs
12:00PM EDT :: 456.cp Oct 30 :: 842.34cp (12.70%) php-cgi :: 29.83 secs
(no data available) Oct 29 :: 767.09cp (14.15%) php-cgi :: 29.79 secs
(no data available) Oct 28 :: 734.20cp (13.09%) php-cgi :: 29.77 secs
(no data available) Oct 27 :: 703.53cp (10.92%) php-cgi :: 29.75 secs
Displaying top utilization processes for user as recorded by cPanel and dcpumon
Top Process %CPU 107 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
Top Process %CPU 102 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
Top Process %CPU 101 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
RADS has detected these custom cron jobs currently enabled for this account
SHELL="/bin/bash"
* * * * * cd /home/tdmfgi5/public_html; php /home/tdmfgi5/public_html/cron.php > /dev/null
2 23 * * 0 /usr/local/bin/imap-archiver -p -q
USER QUERIES TIME LOCKTIME ROWSSENT ROWSRECVD
ERROR: Could not locate any bandwidth data for tdmfgi5 in /var/cpanel/bandwidth/
>>> /opt/sharedrads/nlp tdmfgi5 -p -w 80 --today
Using /var/log/apache2/domlogs/tdmfgi5/pur-tungsten.tdmfginc.com
[1;35m-Hourly hits (04/Nov/2017)------------------------------------------------------[0m
08: 161 09: 171 10: 161 11: 176 12: 166 13: 152 14: 98
[1;35m-HTTP response codes------------------------------------------------------------[0m
200: 1017 301: 21 302: 28 304: 1 404: 14 406: 4
[1;35m-Duplicate requests + response codes--------------------------------------------[0m
458 200 GET /2015/11/02/hello-world/
189 200 GET /2014/07/06/audio-post-format/
39 200 GET /product/maxi-belt/
26 200 POST /wp-login.php
24 200 GET /wp-login.php
23 200 GET /product/vanity-case/
17 200 GET /product/pur-tungsten-jigging-spoon/
16 200 GET /
16 302 POST /wp-comments-post.php
14 200 GET /product/glitterglam-belt/
[1;35m-Requests for non-static content------------------------------------------------[0m
458 200 GET /2015/11/02/hello-world/
189 200 GET /2014/07/06/audio-post-format/
39 200 GET /product/maxi-belt/
36 200 GET /wp-login.php
26 200 POST /wp-login.php
23 200 GET /product/vanity-case/
21 200 GET /
17 200 GET /product/pur-tungsten-jigging-spoon/
16 302 POST /wp-comments-post.php
14 200 GET /product/glitterglam-belt/
[1;35m-Top user agents----------------------------------------------------------------[0m
45 "Opera/9.80 (Windows NT 6.2; Win64; x64) Presto/2.12.388 Version/12.17"
39 "Mozilla/5.0 (iPhone; CPU iPhone OS 10_3_2 like Mac OS X) AppleWebKit/602.1
32 "Mozilla/5.0 (Windows NT 6.0; rv:34.0) Gecko/20100101 Firefox/34.0"
28 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/603.2.5 (KHTML
27 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chr
25 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_4) AppleWebKit/537.36 (KHTML,
22 "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
19 "Mozilla/5.0 (iPad; CPU OS 9_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML,
19 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like
19 "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:54.0) Gecko/20100101 Firefox/
[1;35m-Top IPs with PTR records-------------------------------------------------------[0m
47 125.27.21.181 node-4ad.pool-125-27.dynamic.totbb.net.
39 172.97.28.237 172-97-28-237.dsl.foothillsbroadband.com.
31 118.174.174.112 node-2uo.pool-118-174.dynamic.totbb.net.
23 101.109.129.85 node-pjp.pool-101-109.dynamic.totbb.net.
23 125.27.23.146 node-4nm.pool-125-27.dynamic.totbb.net.
19 192.241.134.44 No Record Found
14 46.161.9.41 No Record Found
13 1.0.184.133 node-b5x.pool-1-0.dynamic.totbb.net.
13 125.27.122.189 node-o8t.pool-125-27.dynamic.totbb.net.
12 154.16.3.55 No Record Found
>>> /opt/sharedrads/recent-cp tdmfgi5 -b
[2K+---------+------------------+------------------+------------------+------------------+
| command | 1m | [4m5m[0m | 15m | 60m |
+---------+------------------+------------------+------------------+------------------+
| pop3 | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% | 0.54s 0.0% |
| imap | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% |
| exim | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% | 0.01s 0.0% |
| bash | 0.00s 2.0% | 0.01s 0.0% | 0.02s 0.0% | 0.06s 0.0% |
| pyzor | 0.00s 0.0% | 0.13s 0.2% | 0.13s 0.0% | 0.41s 0.0% |
| php | 0.05s 98.0% | 0.30s 0.4% | 0.82s 0.3% | 3.32s 0.2% |
| php-cgi | 0.00s 0.0% | 67.82s 99.4% | 291.26s 99.7% | 2027.55s 99.8% |
+---------+------------------+------------------+------------------+------------------+
| total | 0.05s 100.0% | 68.26s 100.0% | 292.23s 100.0% | 2031.89s 100.0% |
+---------+------------------+------------------+------------------+------------------+
s = processs user time in cpu seconds, cp = user time + system time in cpu minutes
>>> Running processes prior to suspension
USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
tdmfgi5 14113 0.0 0.0 85888 4320 ? S 14:12 0:00 dovecot/imap
tdmfgi5 92835 32.9 0.0 0 0 ? Z 14:42 0:13 [php-cgi] <defunct>
tdmfgi5 93014 42.3 0.0 0 0 ? Z 14:42 0:14 [php-cgi] <defunct>
tdmfgi5 126300 0.0 0.0 86228 4684 ? S 13:41 0:00 dovecot/imap