Current File : /home/tdmfgi5/.imh/str_2018-11-08_12:43:27 |
>>> /opt/sharedrads/check_user tdmfgi5 --plaintext
#################################################################################
INMOTION HOSTING .:: SHARED RADS ::. SHARED RESOURCE ABUSE DETECTION SCRIPTS
#################################################################################
Thu Nov 8 12:43:05 EST 2018
Displaying today's most recent CPU usage data as recorded by process accounting
CPU minutes: 161.64cp (1.86%) Actual time: 3026.20re (0.24%)
(since my last data poll @ 12:07 EST tdmfgi5 burned another ~25 cp)
# of executions for CPU intensive processes that have been spawned by this user today
php: 3129 perl: 0 imap: 488 pop3: 0 exim: 738 boxtrap: 0 ftp: 0 cron: 0
CPU minutes used today Historical CPU usage data Most expensive processes
12:00AM EST :: 0.20cp Nov 07 :: 254.89cp (1.81%) php-cgi :: 279.89 secs
03:00AM EST :: 19.2cp Nov 06 :: 201.04cp (1.46%) php-cgi :: 249.67 secs
06:00AM EST :: 79.0cp Nov 05 :: 215.79cp (1.59%) php-cgi :: 248.88 secs
09:00AM EST :: 103.cp Nov 04 :: 157.76cp (1.29%) php-cgi :: 237.09 secs
12:00PM EST :: 136.cp Nov 03 :: 139.76cp (1.17%) php-cgi :: 169.77 secs
03:00PM EST :: 434.cp Nov 02 :: 251.14cp (1.74%) php-cgi :: 26.67 secs
06:00PM EST :: 544.cp Nov 01 :: 282.58cp (1.75%) php-cgi :: 26.67 secs
09:00PM EST :: 641.cp Oct 31 :: 208.03cp (1.39%) php-cgi :: 25.86 secs
Displaying top utilization processes for user as recorded by cPanel and dcpumon
Top Process %CPU 137 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/wp-admin/admin-ajax.php
Top Process %CPU 131 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
Top Process %CPU 109 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
RADS has detected these custom cron jobs currently enabled for this account
SHELL="/bin/bash"
* * * * * cd /home/tdmfgi5/public_html; php /home/tdmfgi5/public_html/cron.php > /dev/null
2 23 * * 0 /usr/local/bin/imap-archiver -p -q
USER QUERIES TIME LOCKTIME ROWSSENT ROWSRECVD
tdmfgi5 1 5 0 0 0
ERROR: Could not locate any bandwidth data for tdmfgi5 in /var/cpanel/bandwidth/
>>> /opt/sharedrads/nlp tdmfgi5 -p -w 80 --today
Using /var/log/apache2/domlogs/tdmfgi5/tdmfginc.com
[1;35m-Hourly hits (08/Nov/2018)------------------------------------------------------[0m
07: 32 08: 1206 09: 376 10: 375 11: 158 12: 117
[1;35m-HTTP response codes------------------------------------------------------------[0m
200: 1087 301: 16 302: 9 304: 40 401: 2 404: 13 405: 1
406: 1094 503: 2
[1;35m-Duplicate requests + response codes--------------------------------------------[0m
1092 406 POST /xmlrpc.php
177 200 POST /wp-admin/admin-ajax.php
34 200 GET /
18 200 GET /favicon.ico
15 200 GET /wp-includes/js/wp-emoji-release.min.js?ver=4.7.11
14 200 GET /wp-content/plugins/revslider/public/assets/js/extensions/revol
14 200 GET /wp-includes/js/jquery/jquery.js?ver=1.12.4
13 200 GET /wp-content/plugins/revslider/public/assets/js/extensions/revol
13 200 GET /wp-content/uploads/2017/04/Group-1.png
12 200 GET /portfolio-item/tig-welding-tungsten-electrodes
[1;35m-Requests for non-static content------------------------------------------------[0m
1092 406 POST /xmlrpc.php
177 200 POST /wp-admin/admin-ajax.php
51 200 GET /
20 200 POST /wp-cron.php
12 200 GET /portfolio-item/tig-welding-tungsten-electrodes
11 200 GET /wp-admin/post.php
9 200 GET /wp-content/themes/betheme/fonts/mfn-icons.woff
9 404 GET /
7 200 GET /wp-admin/admin-ajax.php
6 200 GET /products
[1;35m-Top user agents----------------------------------------------------------------[0m
1097 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik
560 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:63.0) Gecko/20100101 Fir
88 "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko"
60 "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; MDDRJS; rv:11.0) like G
50 "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chr
50 "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like
45 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_4) AppleWebKit/605.1.15 (KH
44 "Mozilla/5.0 (iPhone; CPU iPhone OS 12_0_1 like Mac OS X) AppleWebKit/605
42 "Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/5.0)"
34 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik
[1;35m-Top IPs with PTR records-------------------------------------------------------[0m
1097 158.69.162.109 ip109.ip-158-69-162.net.
561 69.249.56.194 c-69-249-56-194.hsd1.pa.comcast.net.
61 24.3.29.86 c-24-3-29-86.hsd1.pa.comcast.net.
50 24.187.248.58 trinitymilltool.com.
50 74.101.135.32 pool-74-101-135-32.nycmny.fios.verizon.net.
45 66.211.225.58 66-211-225-58.static.velocity.net.
44 216.176.71.250 static-216-176-71-250.consolidated.net.
44 68.80.62.144 c-68-80-62-144.hsd1.pa.comcast.net.
43 34.209.175.228 ec2-34-209-175-228.us-west-2.compute.amazonaws.com.
42 34.209.182.200 ec2-34-209-182-200.us-west-2.compute.amazonaws.com.
>>> /opt/sharedrads/recent-cp tdmfgi5 -b
[2K+----------+------------------+------------------+------------------+------------------+
| command | 1m | [4m5m[0m | 15m | 60m |
+----------+------------------+------------------+------------------+------------------+
| webmaild | 0.00s 0.0% | 0.00s 0.0% | 0.13s 0.1% | 0.71s 0.0% |
| exim | 0.00s 0.0% | 0.00s 0.0% | 0.02s 0.0% | 0.09s 0.0% |
| bash | 0.00s 0.8% | 0.01s 0.1% | 0.02s 0.0% | 0.06s 0.0% |
| pop3 | 0.00s 0.0% | 0.03s 0.4% | 1.37s 0.8% | 30.82s 1.7% |
| pyzor | 0.00s 0.0% | 0.24s 3.7% | 1.29s 0.7% | 8.03s 0.4% |
| imap | 0.00s 0.0% | 0.31s 4.8% | 2.30s 1.3% | 6.39s 0.4% |
| php-cgi | 0.13s 99.2% | 5.84s 90.9% | 172.05s 97.1% | 1751.32s 97.4% |
+----------+------------------+------------------+------------------+------------------+
| total | 0.13s 100.0% | 6.42s 100.0% | 177.18s 100.0% | 1797.42s 100.0% |
+----------+------------------+------------------+------------------+------------------+
s = processs user time in cpu seconds, cp = user time + system time in cpu minutes
>>> Running processes prior to suspension
USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
tdmfgi5 192611 0.0 0.0 88464 4744 ? S 12:41 0:00 dovecot/imap
tdmfgi5 194511 1.0 0.0 90416 6908 ? S 12:41 0:01 dovecot/imap
tdmfgi5 196942 0.0 0.0 88132 4408 ? S 12:42 0:00 dovecot/imap
tdmfgi5 196971 0.0 0.0 88812 4932 ? S 12:42 0:00 dovecot/imap
tdmfgi5 3880380 0.0 0.0 92440 9224 ? S 10:45 0:00 dovecot/imap
tdmfgi5 4181584 0.0 0.0 88584 4948 ? S 11:55 0:00 dovecot/imap
tdmfgi5 4191718 0.0 0.0 88652 5464 ? S 11:58 0:00 dovecot/imap