Current File : /home/tdmfgi5/.imh/str_2019-03-05_13:43:11 |
>>> /opt/sharedrads/check_user tdmfgi5 --plaintext
#################################################################################
INMOTION HOSTING .:: SHARED RADS ::. SHARED RESOURCE ABUSE DETECTION SCRIPTS
#################################################################################
Tue Mar 5 13:43:02 EST 2019
Displaying today's most recent CPU usage data as recorded by process accounting
CPU minutes: 83.50cp (1.92%) Actual time: 8236.66re (0.85%)
(since my last data poll @ 12:07 EST tdmfgi5 burned another ~36 cp)
# of executions for CPU intensive processes that have been spawned by this user today
php: 3455 perl: 0 imap: 1349 pop3: 0 exim: 620 boxtrap: 0 ftp: 0 cron: 0
CPU minutes used today Historical CPU usage data Most expensive processes
12:00AM EST :: 0.20cp Mar 04 :: 78.83cp (1.04%) php-cgi :: 46.59 secs
03:00AM EST :: 11.8cp Mar 03 :: 66.64cp (1.10%) php-cgi :: 45.41 secs
06:00AM EST :: 23.2cp Mar 02 :: 80.50cp (1.37%) php-cgi :: 45.11 secs
09:00AM EST :: 37.1cp Mar 01 :: 84.75cp (1.18%) php-cgi :: 45.07 secs
12:00PM EST :: 47.7cp Feb 28 :: 77.82cp (1.16%) php-cgi :: 41.53 secs
(no data available) Feb 27 :: 86.28cp (1.21%) php-cgi :: 37.49 secs
(no data available) Feb 26 :: 96.39cp (1.38%) php-cgi :: 37.41 secs
(no data available) Feb 25 :: 104.36cp (1.50%) php-cgi :: 22.39 secs
Displaying top utilization processes for user as recorded by cPanel and dcpumon
Top Process %CPU 135 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
Top Process %CPU 100 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
Top Process %CPU 97.6 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/ipsumseo.com/wp-admin/admin-ajax.php
RADS has detected these custom cron jobs currently enabled for this account
SHELL="/bin/bash"
* * * * * cd /home/tdmfgi5/public_html; php /home/tdmfgi5/public_html/cron.php > /dev/null
2 23 * * 0 /usr/local/bin/imap-archiver -p -q
USER QUERIES TIME LOCKTIME ROWSSENT ROWSRECVD
ERROR: Could not locate any bandwidth data for tdmfgi5 in /var/cpanel/bandwidth/
>>> /opt/sharedrads/nlp tdmfgi5 -p -w 80 --today
Using /var/log/apache2/domlogs/tdmfgi5/pur-tungsten.tdmfginc.com-ssl_log
[1;35m-Hourly hits (05/Mar/2019)------------------------------------------------------[0m
07: 58 08: 140 09: 106 10: 92 11: 82 12: 167 13: 3606
[1;35m-HTTP response codes------------------------------------------------------------[0m
200: 3574 301: 116 302: 63 304: 3 400: 1 401: 2 404: 173
405: 5 500: 250 503: 64
[1;35m-Duplicate requests + response codes--------------------------------------------[0m
186 200 GET /s/8c8471.js
185 200 GET /s/842c8f.js
185 200 GET /wp-content/uploads/2017/12/pt-original-logo2-u32558.png
184 200 GET /s/68e3d4.js
183 200 GET /wp-content/uploads/2018/08/ptlogo2-206x90.png
128 200 POST /?wc-ajax=get_refreshed_fragments
111 200 POST /wp-admin/admin-ajax.php
99 200 GET /s/f21e00.js
86 200 GET /s/91353a.js
85 200 GET /s/383607.js
[1;35m-Requests for non-static content------------------------------------------------[0m
191 200 POST /wp-cron.php
130 200 POST /
120 200 GET /wp-json/oembed/1.0/embed
112 200 POST /wp-admin/admin-ajax.php
106 301 GET /
73 200 GET /
43 404 GET /2015/11/02/hello-world/
39 500 POST /
35 500 POST /wp-cron.php
33 200 GET /wp-login.php
[1;35m-Top user agents----------------------------------------------------------------[0m
3080 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik
251 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_0) AppleWebKit/537.36 (KHTM
230 "WordPress/4.9.9; https://pur-tungsten.com"
164 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:65.0) Gecko/20100101 Fir
79 "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.2) Gecko/200907
64 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik
62 "Opera/9.80 (Windows NT 6.2; Win64; x64) Presto/2.12.388 Version/12.17"
24 "Mozilla/5.0 (Linux; Android 8.0.0; SM-G955U) AppleWebKit/537.36 (KHTML,
21 "Mozilla/5.0 (iPhone; CPU iPhone OS 12_1 like Mac OS X) AppleWebKit/605.1
20 "Mozilla/5.0 (Linux; Android 9; SM-G965U) AppleWebKit/537.36 (KHTML, like
[1;35m-Top IPs with PTR records-------------------------------------------------------[0m
273 40.112.170.209 No Record Found
257 64.62.158.117 Query Timed Out
251 65.19.141.114 No Record Found
230 144.208.76.152 ecld208.inmotionhosting.com.
220 216.218.147.202 No Record Found
205 40.85.151.71 No Record Found
201 104.42.76.67 No Record Found
197 35.184.4.217 217.4.184.35.bc.googleusercontent.com.
164 69.249.56.194 c-69-249-56-194.hsd1.pa.comcast.net.
158 65.19.141.115 No Record Found
>>> /opt/sharedrads/recent-cp tdmfgi5 -b
[2K+-------------+------------------+------------------+------------------+------------------+
| command | 1m | [4m5m[0m | 15m | 60m |
+-------------+------------------+------------------+------------------+------------------+
| pyzor | 0.00s 0.0% | 0.00s 0.0% | 0.08s 0.0% | 1.97s 0.1% |
| exim | 0.00s 0.0% | 0.00s 0.0% | 0.08s 0.0% | 0.12s 0.0% |
| dovecot-lda | 0.00s 0.0% | 0.00s 0.0% | 0.03s 0.0% | 0.03s 0.0% |
| webmaild | 0.00s 0.0% | 0.00s 0.0% | 0.04s 0.0% | 0.29s 0.0% |
| pop3 | 0.00s 0.0% | 0.00s 0.0% | 0.01s 0.0% | 1.78s 0.1% |
| bash | 0.00s 0.8% | 0.01s 0.0% | 0.02s 0.0% | 0.06s 0.0% |
| imap | 0.00s 0.0% | 0.03s 0.0% | 1.55s 0.2% | 4.87s 0.2% |
| php-cgi | 0.12s 99.2% | 204.29s 100.0% | 803.52s 99.8% | 2023.38s 99.6% |
+-------------+------------------+------------------+------------------+------------------+
| total | 0.12s 100.0% | 204.33s 100.0% | 805.33s 100.0% | 2032.50s 100.0% |
+-------------+------------------+------------------+------------------+------------------+
s = processs user time in cpu seconds, cp = user time + system time in cpu minutes
>>> Running processes prior to suspension
USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
tdmfgi5 1043 0.0 0.0 92784 7280 ? S 11:20 0:00 dovecot/imap
tdmfgi5 7828 0.0 0.0 87016 5656 ? S 13:14 0:00 dovecot/imap
tdmfgi5 9536 0.0 0.0 86416 4736 ? S 13:14 0:00 dovecot/imap
tdmfgi5 73321 0.0 0.0 86620 5412 ? S 13:26 0:00 dovecot/imap
tdmfgi5 84639 0.0 0.0 86432 5040 ? S 13:28 0:00 dovecot/imap
tdmfgi5 110348 0.0 0.0 86560 5140 ? S 13:33 0:00 dovecot/imap
tdmfgi5 110384 0.0 0.0 86084 4400 ? S 13:33 0:00 dovecot/imap
tdmfgi5 131527 0.0 0.0 86880 5660 ? S 10:32 0:00 dovecot/imap
tdmfgi5 140096 0.0 0.0 86084 4404 ? S 13:39 0:00 dovecot/imap
tdmfgi5 152782 5.0 0.0 353916 93136 ? R 13:42 0:02 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
tdmfgi5 153646 5.1 0.0 396220 129460 ? R 13:42 0:02 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
tdmfgi5 154029 4.8 0.1 348400 136952 ? R 13:42 0:01 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/wp-cron.php
tdmfgi5 154041 4.3 0.0 389504 123408 ? R 13:42 0:01 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
tdmfgi5 154093 4.8 0.0 348844 125316 ? R 13:42 0:01 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/wp-cron.php
tdmfgi5 154381 5.1 0.0 348400 105292 ? R 13:42 0:01 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/wp-cron.php
tdmfgi5 154412 5.0 0.0 389236 122996 ? R 13:42 0:01 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
tdmfgi5 154440 4.2 0.0 378028 111712 ? R 13:42 0:01 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
tdmfgi5 154555 0.0 0.0 86844 5264 ? S 13:42 0:00 dovecot/imap
tdmfgi5 154592 4.7 0.0 382008 116008 ? R 13:42 0:01 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
tdmfgi5 154710 0.0 0.0 86588 5236 ? S 13:42 0:00 dovecot/imap
tdmfgi5 154711 4.8 0.0 370940 104568 ? R 13:42 0:01 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
tdmfgi5 154778 1.0 0.0 87500 6224 ? S 13:42 0:00 dovecot/imap
tdmfgi5 154978 4.6 0.0 338768 73412 ? R 13:42 0:00 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
tdmfgi5 155087 5.5 0.0 349080 83704 ? R 13:42 0:00 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
tdmfgi5 155118 5.2 0.0 337632 72056 ? R 13:42 0:00 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
tdmfgi5 155665 4.8 0.0 307380 42472 ? R 13:43 0:00 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
tdmfgi5 155951 5.6 0.0 302200 36964 ? R 13:43 0:00 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
tdmfgi5 156338 10.0 0.0 284820 19052 ? R 13:43 0:00 /opt/php55/bin/php-cgi /home/tdmfgi5/public_html/pur-tungsten.com/index.php
tdmfgi5 166309 0.0 0.0 86508 5304 ? S 08:37 0:00 dovecot/imap
tdmfgi5 166779 0.0 0.0 90448 7372 ? S 12:29 0:00 dovecot/imap
tdmfgi5 189470 0.0 0.0 88296 6216 ? S 11:19 0:00 dovecot/imap