Current File : /home/tdmfgi5/.imh/str_2019-07-30_11:43:10 |
>>> /opt/sharedrads/check_user tdmfgi5 --plaintext
#################################################################################
INMOTION HOSTING .:: SHARED RADS ::. SHARED RESOURCE ABUSE DETECTION SCRIPTS
#################################################################################
Tue Jul 30 11:43:02 EDT 2019
Displaying today's most recent CPU usage data as recorded by process accounting
CPU minutes: 104.88cp (3.33%) Actual time: 4110.51re (0.66%)
(since my last data poll @ 09:07 EDT tdmfgi5 burned another ~45 cp)
# of executions for CPU intensive processes that have been spawned by this user today
php: 2732 perl: 0 imap: 443 pop3: 0 exim: 4 boxtrap: 0 ftp: 0 cron: 0
CPU minutes used today Historical CPU usage data Most expensive processes
12:00AM EDT :: 0.17cp Jul 29 :: 159.18cp (1.00%) php-cgi :: 47.11 secs
03:00AM EDT :: 8.09cp Jul 28 :: 179.38cp (2.97%) php-cgi :: 47.10 secs
06:00AM EDT :: 43.5cp Jul 27 :: 189.94cp (3.12%) php-cgi :: 46.99 secs
09:00AM EDT :: 59.9cp Jul 26 :: 246.93cp (3.69%) php-cgi :: 46.85 secs
(no data available) Jul 25 :: 229.35cp (3.60%) php-cgi :: 46.75 secs
(no data available) Jul 24 :: 209.50cp (2.68%) php-cgi :: 45.22 secs
(no data available) Jul 23 :: 222.95cp (2.96%) php-cgi :: 42.89 secs
(no data available) Jul 22 :: 199.23cp (3.24%) php-cgi :: 39.55 secs
Displaying top utilization processes for user as recorded by cPanel and dcpumon
Top Process %CPU 111 /opt/php56/bin/php-cgi /home/tdmfgi5/public_html/tdmfginc.com/index.php
Top Process %CPU 95.2 /opt/php56/bin/php-cgi /home/tdmfgi5/public_html/tdmfginc.com/wp-admin/admin-ajax.php
Top Process %CPU 93.9 /opt/php56/bin/php-cgi /home/tdmfgi5/public_html/ipsumseo.com/wp-admin/admin-ajax.php
RADS has detected these custom cron jobs currently enabled for this account
SHELL="/bin/bash"
* * * * * cd /home/tdmfgi5/public_html; php /home/tdmfgi5/public_html/cron.php > /dev/null
2 23 * * 0 /usr/local/bin/imap-archiver -p -q
USER QUERIES TIME LOCKTIME ROWSSENT ROWSRECVD
ERROR: Could not locate any bandwidth data for tdmfgi5 in /var/cpanel/bandwidth/
>>> /opt/sharedrads/nlp tdmfgi5 -p -w 80 --today
Using /var/log/apache2/domlogs/tdmfgi5/pur-tungsten.tdmfginc.com-ssl_log
[1;35m-Hourly hits (30/Jul/2019)------------------------------------------------------[0m
08: 927 09: 413 10: 1029 11: 401
[1;35m-HTTP response codes------------------------------------------------------------[0m
200: 2173 301: 5 302: 39 304: 504 403: 1 404: 42 405: 1
406: 4 503: 1
[1;35m-Duplicate requests + response codes--------------------------------------------[0m
265 200 POST /wp-admin/admin-ajax.php
54 200 GET /
49 200 POST /?wc-ajax=get_refreshed_fragments
33 200 GET /s/842c8f.js
32 200 GET /s/68e3d4.js
32 200 GET /s/8c8471.js
31 200 GET /wp-content/plugins/file-manager-advanced/application/assets/ico
30 404 GET /2015/11/02/hello-world/
29 200 GET /wp-content/uploads/2017/12/pt-original-logo2-u32558.png
29 200 GET /wp-content/uploads/2019/07/NSSM.png
[1;35m-Requests for non-static content------------------------------------------------[0m
265 200 POST /wp-admin/admin-ajax.php
185 200 POST /wp-cron.php
112 200 GET /
67 200 POST /
31 404 GET /2015/11/02/hello-world/
29 200 GET /wp-admin/load-styles.php
25 200 GET /wp-admin/admin.php
25 200 GET /wp-login.php
24 200 GET /wp-content/plugins/live-composer-page-builder/css/font/fontawes
21 200 GET /wp-admin/admin-ajax.php
[1;35m-Top user agents----------------------------------------------------------------[0m
1129 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:68.0) Gecko/20100101 Fir
234 "'Mozilla/5.0 (compatible; DuckDuckBot-Https/1.1; https://duckduckgo.com/
230 "Mozilla/5.0 (iPhone; CPU iPhone OS 12_3_1 like Mac OS X) AppleWebKit/605
185 "WordPress/4.9.10; https://pur-tungsten.com"
177 "Mozilla/5.0 (Linux; Android 9; SAMSUNG SM-G965U Build/PPR1.180610.011) A
92 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik
67 "Mozilla/5.0 (Linux; Android 9; SM-N960U) AppleWebKit/537.36 (KHTML, like
64 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik
53 "Mozilla/5.0 (iPad; CPU OS 12_3_1 like Mac OS X) AppleWebKit/605.1.15 (KH
51 "Mozilla/5.0 (Linux; Android 6.0.1; SAMSUNG-SM-G870A) AppleWebKit/537.36
[1;35m-Top IPs with PTR records-------------------------------------------------------[0m
1129 76.124.35.212 c-76-124-35-212.hsd1.pa.comcast.net.
235 50.16.241.117 ec2-50-16-241-117.compute-1.amazonaws.com.
185 144.208.76.152 ecld208.inmotionhosting.com.
177 96.4.86.147 static-147-86-4-96.hawkins.tn.ena.net.
92 76.8.207.90 No Record Found
79 174.17.18.22 174-17-18-22.phnx.qwest.net.
68 216.150.106.177 ear-rural-dsl-176.earlsboro.ok.mbo.net.
61 161.97.250.102 Resolver Error
54 172.243.231.16 Query Timed Out
51 174.87.216.41 174-087-216-041.dhcp.chtrptr.net.
>>> /opt/sharedrads/recent-cp tdmfgi5 -b
[2K+-----------+------------------+------------------+------------------+------------------+
| command | 1m | [4m5m[0m | 15m | 60m |
+-----------+------------------+------------------+------------------+------------------+
| rm | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% |
| sendmail | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% |
| cat | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% |
| exim | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% |
| proxyexec | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% |
| webmaild | 0.00s 0.0% | 0.00s 0.0% | 0.05s 0.0% | 0.46s 0.0% |
| whoami | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% | 0.00s 0.0% |
| pop3 | 0.00s 0.0% | 0.00s 0.0% | 1.17s 0.8% | 3.80s 0.2% |
| bash | 0.00s 0.9% | 0.01s 0.0% | 0.02s 0.0% | 0.06s 0.0% |
| imap | 0.00s 0.0% | 0.37s 1.1% | 1.81s 1.3% | 5.03s 0.3% |
| php-cgi | 0.11s 99.1% | 32.80s 98.9% | 135.77s 97.8% | 1879.04s 99.5% |
+-----------+------------------+------------------+------------------+------------------+
| total | 0.11s 100.0% | 33.18s 100.0% | 138.81s 100.0% | 1888.40s 100.0% |
+-----------+------------------+------------------+------------------+------------------+
s = processs user time in cpu seconds, cp = user time + system time in cpu minutes
>>> Running processes prior to suspension
USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
tdmfgi5 2181 0.0 0.0 84508 4664 ? S 11:42 0:00 dovecot/imap
tdmfgi5 30415 0.0 0.0 84988 5716 ? S 09:51 0:00 dovecot/imap
tdmfgi5 34159 0.0 0.0 84844 5336 ? S 11:10 0:00 dovecot/imap
tdmfgi5 99831 0.0 0.0 84908 5716 ? S 11:22 0:00 dovecot/imap
tdmfgi5 123620 0.0 0.0 85228 5828 ? S 10:49 0:00 dovecot/imap
tdmfgi5 145812 0.0 0.0 85080 5824 ? S 11:31 0:00 dovecot/imap
tdmfgi5 170084 0.0 0.0 85228 5720 ? S 11:36 0:00 dovecot/imap
tdmfgi5 178764 0.0 0.0 85788 6532 ? S 10:21 0:00 dovecot/imap
tdmfgi5 181675 0.0 0.0 85200 5824 ? S 11:38 0:00 dovecot/imap
tdmfgi5 181677 0.0 0.0 85196 5192 ? S 11:38 0:00 dovecot/imap
tdmfgi5 184017 0.0 0.0 88516 6060 ? S 11:39 0:00 dovecot/imap
tdmfgi5 186274 0.0 0.0 85192 5440 ? S 11:39 0:00 dovecot/imap
tdmfgi5 193881 0.0 0.0 116416 26388 ? S 11:41 0:00 webmaild - serving 76.124.35.212