Current File : /home/tdmfgi5/.imh/str_2018-09-05_13:43:29 |
>>> /opt/sharedrads/check_user tdmfgi5 --plaintext
#################################################################################
INMOTION HOSTING .:: SHARED RADS ::. SHARED RESOURCE ABUSE DETECTION SCRIPTS
#################################################################################
Wed Sep 5 13:43:05 EDT 2018
Displaying today's most recent CPU usage data as recorded by process accounting
CPU minutes: 180.88cp (1.93%) Actual time: 4424.86re (0.48%)
(since my last data poll @ 12:07 EDT tdmfgi5 burned another ~55 cp)
# of executions for CPU intensive processes that have been spawned by this user today
php: 3155 perl: 0 imap: 473 pop3: 0 exim: 700 boxtrap: 0 ftp: 0 cron: 0
CPU minutes used today Historical CPU usage data Most expensive processes
12:00AM EDT :: 0.35cp Sep 04 :: 256.30cp (1.71%) php-cgi :: 25.86 secs
03:00AM EDT :: 20.2cp Sep 03 :: 191.58cp (1.57%) php-cgi :: 24.56 secs
06:00AM EDT :: 55.6cp Sep 02 :: 189.25cp (1.74%) php-cgi :: 21.79 secs
09:00AM EDT :: 84.7cp Sep 01 :: 168.70cp (1.44%) php-cgi :: 20.93 secs
12:00PM EDT :: 125.cp Aug 31 :: 195.81cp (1.41%) php-cgi :: 20.42 secs
03:00PM EDT :: 339.cp Aug 30 :: 223.59cp (1.59%) php-cgi :: 19.77 secs
06:00PM EDT :: 409.cp Aug 29 :: 265.61cp (1.93%) php-cgi :: 19.60 secs
09:00PM EDT :: 465.cp Aug 28 :: 198.87cp (1.30%) php-cgi :: 19.24 secs
Displaying top utilization processes for user as recorded by cPanel and dcpumon
Top Process %CPU 204 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/wp-admin/edit.php
Top Process %CPU 165 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/wp-login.php
Top Process %CPU 149 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
RADS has detected these custom cron jobs currently enabled for this account
SHELL="/bin/bash"
* * * * * cd /home/tdmfgi5/public_html; php /home/tdmfgi5/public_html/cron.php > /dev/null
2 23 * * 0 /usr/local/bin/imap-archiver -p -q
USER QUERIES TIME LOCKTIME ROWSSENT ROWSRECVD
tdmfgi5 5 18 0 1 5
ERROR: Could not locate any bandwidth data for tdmfgi5 in /var/cpanel/bandwidth/
>>> /opt/sharedrads/nlp tdmfgi5 -p -w 80 --today
Using /var/log/apache2/domlogs/tdmfgi5/pur-tungsten.tdmfginc.com-ssl_log
[1;35m-Hourly hits (05/Sep/2018)------------------------------------------------------[0m
08: 378 09: 525 10: 262 11: 826 12: 1730 13: 1817
[1;35m-HTTP response codes------------------------------------------------------------[0m
200: 4660 206: 6 301: 29 302: 72 304: 599 404: 143 406: 5
421: 13 500: 11
[1;35m-Duplicate requests + response codes--------------------------------------------[0m
363 200 POST /wp-admin/admin-ajax.php
223 200 GET /
51 200 GET /wp-content/uploads/2018/08/ptlogo2-206x90.png
50 404 GET /2015/11/02/hello-world/
49 200 GET /wp-content/uploads/2017/12/pt-original-logo2-u32558.png
48 200 GET /wp-login.php?registration=disabled
48 302 GET /wp-login.php?action=register
46 200 GET /wp-content/plugins/wordpress-seo/css/dist/adminbar-810.min.css?
42 200 GET /wp-content/uploads/2017/12/derby_car_001.jpg
42 200 GET /wp-content/uploads/2018/08/burrball-300x300.jpg
[1;35m-Requests for non-static content------------------------------------------------[0m
370 200 POST /wp-admin/admin-ajax.php
239 200 GET /
55 200 GET /wp-login.php
50 404 GET /2015/11/02/hello-world/
48 302 GET /wp-login.php
37 200 POST /wp-cron.php
36 200 GET /wp-admin/admin.php
34 200 GET /product/jp-enterprises-silent-captured-spring-buffer/
30 200 POST /
30 404 GET /2014/07/06/audio-post-format/
[1;35m-Top user agents----------------------------------------------------------------[0m
3368 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:61.0) Gecko/20100101 Fir
896 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik
388 "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:61.0) Gecko/20100101 Firefo
100 "Opera/9.80 (Windows NT 6.2; Win64; x64) Presto/2.12.388 Version/12.17"
80 "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/53
78 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; G
54 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik
50 "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko"
47 "WordPress/4.9.8; https://pur-tungsten.com"
40 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik
[1;35m-Top IPs with PTR records-------------------------------------------------------[0m
3408 69.249.56.194 c-69-249-56-194.hsd1.pa.comcast.net.
598 166.249.71.7 7.sub-166-249-71.myvzw.com.
434 174.138.71.228 No Record Found
253 71.175.22.114 static-71-175-22-114.phlapa.ftas.verizon.net.
54 66.102.8.5 google-proxy-66-102-8-5.google.com.
52 66.102.8.1 google-proxy-66-102-8-1.google.com.
52 66.102.8.7 google-proxy-66-102-8-7.google.com.
51 35.141.223.245 035-141-223-245.dhcp.bhn.net.
50 64.85.240.30 astound-64-85-240-30.ca.astound.net.
47 144.208.76.152 ecld208.inmotionhosting.com.
>>> /opt/sharedrads/recent-cp tdmfgi5 -b
[2K+-----------------+------------------+------------------+------------------+------------------+
| command | 1m | [4m5m[0m | 15m | 60m |
+-----------------+------------------+------------------+------------------+------------------+
| pyzor | 0.00s 0.0% | 0.00s 0.0% | 0.66s 0.2% | 8.67s 0.5% |
| pure-ftpd | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% | 4.96s 0.3% |
| /usr/local/cpan | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% | 0.55s 0.0% |
| cpanel | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% | 0.54s 0.0% |
| bash | 0.00s 0.0% | 0.01s 0.0% | 0.02s 0.0% | 0.06s 0.0% |
| dovecot-lda | 0.00s 0.0% | 0.06s 0.0% | 0.06s 0.0% | 0.09s 0.0% |
| exim | 0.00s 0.0% | 0.12s 0.1% | 0.13s 0.0% | 0.29s 0.0% |
| imap | 0.00s 0.0% | 0.29s 0.2% | 0.55s 0.1% | 5.35s 0.3% |
| pop3 | 0.00s 0.0% | 2.74s 2.0% | 10.41s 2.7% | 17.75s 1.0% |
| php-cgi | 5.19s 100.0% | 134.97s 97.7% | 371.84s 96.9% | 1817.20s 97.9% |
+-----------------+------------------+------------------+------------------+------------------+
| total | 5.19s 100.0% | 138.18s 100.0% | 383.66s 100.0% | 1855.47s 100.0% |
+-----------------+------------------+------------------+------------------+------------------+
s = processs user time in cpu seconds, cp = user time + system time in cpu minutes
>>> Running processes prior to suspension
USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
tdmfgi5 459031 0.0 0.0 91812 6140 ? S 11:03 0:00 dovecot/imap
tdmfgi5 665987 0.0 0.0 88564 5252 ? S 11:50 0:00 dovecot/imap
tdmfgi5 742663 0.0 0.0 88776 5612 ? S 12:06 0:00 dovecot/imap
tdmfgi5 752177 0.0 0.0 88972 5768 ? S 12:08 0:00 dovecot/imap
tdmfgi5 961895 0.0 0.0 88584 5140 ? S 12:56 0:00 dovecot/imap
tdmfgi5 1013396 0.0 0.0 88268 4668 ? S 13:08 0:00 dovecot/imap