Current File : /home/tdmfgi5/.imh/str_2018-01-03_18:43:13 |
>>> /opt/sharedrads/check_user tdmfgi5 --plaintext
#################################################################################
INMOTION HOSTING .:: SHARED RADS ::. SHARED RESOURCE ABUSE DETECTION SCRIPTS
#################################################################################
Wed Jan 3 18:43:02 EST 2018
Displaying today's most recent CPU usage data as recorded by process accounting
CPU minutes: 542.92cp (8.50%) Actual time: 8212.36re (0.39%)
(since my last data poll @ 18:07 EST tdmfgi5 burned another ~21 cp)
# of executions for CPU intensive processes that have been spawned by this user today
php: 4467 perl: 0 imap: 1621 pop3: 0 exim: 1242 boxtrap: 0 ftp: 0 cron: 0
CPU minutes used today Historical CPU usage data Most expensive processes
12:00AM EST :: 0.39cp Jan 02 :: 747.49cp (9.97%) php-cgi :: 149.76 secs
03:00AM EST :: 92.0cp Jan 01 :: 645.83cp (11.76%) php-cgi :: 30.66 secs
06:00AM EST :: 174.cp Dec 31 :: 574.34cp (11.01%) php-cgi :: 30.63 secs
09:00AM EST :: 287.cp Dec 30 :: 548.55cp (10.15%) php-cgi :: 30.62 secs
12:00PM EST :: 386.cp Dec 29 :: 412.76cp (7.26%) php-cgi :: 30.60 secs
03:00PM EST :: 455.cp Dec 28 :: 528.73cp (8.22%) php-cgi :: 30.57 secs
06:00PM EST :: 521.cp Dec 27 :: 441.03cp (7.10%) php-cgi :: 30.56 secs
09:00PM EST :: 160.cp Dec 26 :: 446.95cp (7.43%) php-cgi :: 30.56 secs
Displaying top utilization processes for user as recorded by cPanel and dcpumon
Top Process %CPU 146 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
Top Process %CPU 140 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
Top Process %CPU 122 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/ipsumseo.com/wp-admin/admin-ajax.php
RADS has detected these custom cron jobs currently enabled for this account
SHELL="/bin/bash"
* * * * * cd /home/tdmfgi5/public_html; php /home/tdmfgi5/public_html/cron.php > /dev/null
2 23 * * 0 /usr/local/bin/imap-archiver -p -q
USER QUERIES TIME LOCKTIME ROWSSENT ROWSRECVD
tdmfgi5 5 24 0 0 4
ERROR: Could not locate any bandwidth data for tdmfgi5 in /var/cpanel/bandwidth/
>>> /opt/sharedrads/nlp tdmfgi5 -p -w 80 --today
Using /var/log/apache2/domlogs/tdmfgi5/pur-tungsten.tdmfginc.com
[1;35m-Hourly hits (03/Jan/2018)------------------------------------------------------[0m
07: 440 08: 343 09: 207 10: 152 11: 193 12: 97 13: 112 14: 97 15: 98
16: 86 17: 132 18: 109
[1;35m-HTTP response codes------------------------------------------------------------[0m
200: 1771 301: 58 302: 150 304: 2 404: 41 406: 39 429: 5
[1;35m-Duplicate requests + response codes--------------------------------------------[0m
418 200 GET /2015/11/02/hello-world/
214 200 GET /2014/07/06/audio-post-format/
129 302 POST /wp-comments-post.php
61 200 GET /product/pur-tungsten-jigs/
50 200 GET /product/glitterglam-belt/
48 200 GET /product/pur-tungsten-jigging-spoon/
46 200 GET /product/maxi-belt/
42 200 GET /
41 200 GET /product/vanity-case/
35 200 GET /product/pur-tungsten-ice-fishing-jigs/
[1;35m-Requests for non-static content------------------------------------------------[0m
419 200 GET /2015/11/02/hello-world/
214 200 GET /2014/07/06/audio-post-format/
129 302 POST /wp-comments-post.php
61 200 GET /product/pur-tungsten-jigs/
50 200 GET /product/glitterglam-belt/
49 200 GET /
48 200 GET /product/pur-tungsten-jigging-spoon/
46 200 GET /product/maxi-belt/
41 200 GET /product/vanity-case/
36 200 GET /wp-login.php
[1;35m-Top user agents----------------------------------------------------------------[0m
276 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like
132 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/601.6.17 (KHT
93 "Opera/9.80 (Windows NT 6.2; Win64; x64) Presto/2.12.388 Version/12.17"
56 "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko"
48 "Mozilla/5.0 (compatible; AhrefsBot/5.2; +http://ahrefs.com/robot/)"
35 "Mozilla/5.0 (Linux; U; Android 2.2) AppleWebKit/533.1 (KHTML, like Gecko)
25 "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like
25 "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like
24 "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like
21 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ch
[1;35m-Top IPs with PTR records-------------------------------------------------------[0m
254 37.215.175.136 mm-136-175-215-37.mfilial.dynamic.pppoe.byfly.by.
132 35.193.117.48 48.117.193.35.bc.googleusercontent.com.
81 37.215.66.176 mm-176-66-215-37.mfilial.dynamic.pppoe.byfly.by.
69 35.188.160.69 69.160.188.35.bc.googleusercontent.com.
69 35.202.252.115 115.252.202.35.bc.googleusercontent.com.
69 35.224.191.245 245.191.224.35.bc.googleusercontent.com.
69 35.226.56.229 229.56.226.35.bc.googleusercontent.com.
64 198.255.114.202 No Record Found
47 37.215.83.179 mm-179-83-215-37.mfilial.dynamic.pppoe.byfly.by.
45 163.172.65.215 163-172-65-215.rev.poneytelecom.eu.
>>> /opt/sharedrads/recent-cp tdmfgi5 -b
[2K+---------+------------------+------------------+------------------+------------------+
| command | 1m | [4m5m[0m | 15m | 60m |
+---------+------------------+------------------+------------------+------------------+
| imap | 0.00s 0.0% | 0.00s 0.0% | 0.53s 0.1% | 1.31s 0.1% |
| pop3 | 0.00s 0.0% | 0.00s 0.0% | 1.43s 0.3% | 2.17s 0.1% |
| exim | 0.00s 0.0% | 0.00s 0.0% | 0.02s 0.0% | 0.06s 0.0% |
| bash | 0.00s 0.1% | 0.01s 0.0% | 0.02s 0.0% | 0.06s 0.0% |
| pyzor | 0.00s 0.0% | 0.07s 0.1% | 0.26s 0.1% | 1.74s 0.1% |
| php | 0.06s 8.0% | 0.30s 0.4% | 0.90s 0.2% | 3.49s 0.2% |
| php-cgi | 0.69s 91.9% | 71.95s 99.5% | 425.93s 99.3% | 1795.39s 99.5% |
+---------+------------------+------------------+------------------+------------------+
| total | 0.75s 100.0% | 72.33s 100.0% | 429.08s 100.0% | 1804.22s 100.0% |
+---------+------------------+------------------+------------------+------------------+
s = processs user time in cpu seconds, cp = user time + system time in cpu minutes
>>> Running processes prior to suspension
USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
tdmfgi5 7742 0.0 0.0 88064 4428 ? S 18:29 0:00 dovecot/imap
tdmfgi5 54874 0.0 0.0 88404 4684 ? S 17:44 0:00 dovecot/imap
tdmfgi5 71413 0.0 0.0 88516 5188 ? S 17:49 0:00 dovecot/imap
tdmfgi5 173691 0.0 0.0 88748 4948 ? S 18:20 0:00 dovecot/imap