Current File : /home/tdmfgi5/.imh/str_2018-07-25_15:43:52 |
>>> /opt/sharedrads/check_user tdmfgi5 --plaintext
#################################################################################
INMOTION HOSTING .:: SHARED RADS ::. SHARED RESOURCE ABUSE DETECTION SCRIPTS
#################################################################################
Wed Jul 25 15:43:29 EDT 2018
Displaying today's most recent CPU usage data as recorded by process accounting
CPU minutes: 163.24cp (1.42%) Actual time: 3989.50re (0.35%)
(since my last data poll @ 15:07 EDT tdmfgi5 burned another ~13 cp)
# of executions for CPU intensive processes that have been spawned by this user today
php: 4200 perl: 0 imap: 598 pop3: 0 exim: 1081 boxtrap: 0 ftp: 1 cron: 0
CPU minutes used today Historical CPU usage data Most expensive processes
12:00AM EDT :: 0.14cp Jul 24 :: 221.92cp (1.40%) php-cgi :: 25.03 secs
03:00AM EDT :: 18.6cp Jul 23 :: 197.91cp (1.26%) php-cgi :: 23.69 secs
06:00AM EDT :: 39.5cp Jul 22 :: 129.92cp (1.10%) php-cgi :: 23.35 secs
09:00AM EDT :: 59.2cp Jul 21 :: 148.57cp (1.22%) php-cgi :: 22.94 secs
12:00PM EDT :: 85.8cp Jul 20 :: 209.97cp (1.41%) php-cgi :: 22.19 secs
03:00PM EDT :: 150.cp Jul 19 :: 180.78cp (1.17%) php-cgi :: 22.04 secs
06:00PM EDT :: 314.cp Jul 18 :: 137.66cp (0.87%) php-cgi :: 21.89 secs
09:00PM EDT :: 366.cp Jul 17 :: 196.80cp (1.25%) php-cgi :: 21.33 secs
Displaying top utilization processes for user as recorded by cPanel and dcpumon
Top Process %CPU 165 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
Top Process %CPU 159 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/wp-login.php
Top Process %CPU 129 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/tdmfginc.com/wp-cron.php
RADS has detected these custom cron jobs currently enabled for this account
SHELL="/bin/bash"
* * * * * cd /home/tdmfgi5/public_html; php /home/tdmfgi5/public_html/cron.php > /dev/null
2 23 * * 0 /usr/local/bin/imap-archiver -p -q
USER QUERIES TIME LOCKTIME ROWSSENT ROWSRECVD
ERROR: Could not locate any bandwidth data for tdmfgi5 in /var/cpanel/bandwidth/
>>> /opt/sharedrads/nlp tdmfgi5 -p -w 80 --today
Using /var/log/apache2/domlogs/tdmfgi5/tdmfginc.com
[1;35m-Hourly hits (25/Jul/2018)------------------------------------------------------[0m
08: 12 09: 62 10: 126 11: 282 12: 337 13: 855 14: 669 15: 879
[1;35m-HTTP response codes------------------------------------------------------------[0m
200: 2746 301: 87 302: 17 304: 265 404: 28 406: 1 503: 78
[1;35m-Duplicate requests + response codes--------------------------------------------[0m
351 200 POST /wp-admin/admin-ajax.php
78 503 POST /wp-login.php
36 200 GET /
33 200 GET /robots.txt
24 200 GET /sitemap_index.xml
24 200 GET /wp-includes/js/wp-emoji-release.min.js?ver=4.7.11
21 200 GET /about-us
21 200 GET /wp-content/plugins/revslider/public/assets/js/extensions/revolu
19 200 GET /wp-content/plugins/revslider/public/assets/js/extensions/revolu
19 200 GET /wp-includes/js/jquery/jquery.js?ver=1.12.4
[1;35m-Requests for non-static content------------------------------------------------[0m
352 200 POST /wp-admin/admin-ajax.php
92 200 POST /wp-cron.php
78 503 POST /wp-login.php
53 200 GET /
41 200 POST /
25 200 GET /request-a-quote
23 200 GET /wp-admin/post.php
22 200 GET /about-us
20 301 GET /request-a-quote/
18 200 GET /wp-admin/load-scripts.php
[1;35m-Top user agents----------------------------------------------------------------[0m
1950 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:61.0) Gecko/20100101 Fir
427 "Screaming Frog SEO Spider/9.4"
235 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik
143 "WordPress/4.7.11; http://tdmfginc.com"
76 "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gec
57 "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Geck
50 "Mozilla/5.0 (iPhone; CPU iPhone OS 10_3_2 like Mac OS X) AppleWebKit/603
50 "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chr
42 "Mozilla/5.0 (compatible; Dataprovider.com/vacancies;)"
32 "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Ge
[1;35m-Top IPs with PTR records-------------------------------------------------------[0m
2377 69.249.56.194 c-69-249-56-194.hsd1.pa.comcast.net.
190 71.175.22.114 static-71-175-22-114.phlapa.ftas.verizon.net.
143 144.208.76.152 ecld208.inmotionhosting.com.
76 91.210.146.208 208.146.dynamic.PPPoE.fregat.ua.
57 24.199.136.122 rrcs-24-199-136-122.midsouth.biz.rr.com.
50 67.253.179.74 cpe-67-253-179-74.rochester.res.rr.com.
45 174.138.71.228 No Record Found
33 144.29.1.26 proxy-02.basf.us.
30 157.32.114.34 No Record Found
22 66.249.66.41 crawl-66-249-66-41.googlebot.com.
>>> /opt/sharedrads/recent-cp tdmfgi5 -b
[2K+-------------+------------------+------------------+------------------+------------------+
| command | 1m | [4m5m[0m | 15m | 60m |
+-------------+------------------+------------------+------------------+------------------+
| dovecot-lda | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% | 0.12s 0.0% |
| pop3 | 0.00s 0.0% | 0.00s 0.0% | 11.41s 2.8% | 34.79s 1.8% |
| exim | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% | 0.18s 0.0% |
| bash | 0.00s 0.0% | 0.01s 0.0% | 0.02s 0.0% | 0.06s 0.0% |
| imap | 0.00s 0.0% | 0.05s 0.1% | 1.66s 0.4% | 7.19s 0.4% |
| pyzor | 0.00s 0.0% | 0.54s 0.6% | 0.54s 0.1% | 9.31s 0.5% |
| php-cgi | 13.88s 100.0% | 90.31s 99.3% | 399.85s 96.7% | 1858.19s 97.3% |
+-------------+------------------+------------------+------------------+------------------+
| total | 13.88s 100.0% | 90.91s 100.0% | 413.48s 100.0% | 1909.84s 100.0% |
+-------------+------------------+------------------+------------------+------------------+
s = processs user time in cpu seconds, cp = user time + system time in cpu minutes
>>> Running processes prior to suspension
USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
tdmfgi5 1438631 0.0 0.0 88832 5640 ? S 09:45 0:00 dovecot/imap
tdmfgi5 1721945 0.0 0.0 91436 5880 ? S 11:02 0:00 dovecot/imap
tdmfgi5 2569253 0.0 0.0 88872 5644 ? S 14:51 0:01 dovecot/imap
tdmfgi5 2630363 0.0 0.0 89324 6088 ? S 15:07 0:00 dovecot/imap
tdmfgi5 2639374 0.0 0.0 88576 5068 ? S 15:09 0:00 dovecot/imap
tdmfgi5 2663956 0.0 0.0 88260 4680 ? S 15:16 0:00 dovecot/imap
tdmfgi5 2758327 0.0 0.0 325520 58468 ? R 15:43 0:00 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/tdmfginc.com/wp-admin/post.php