Current File : /home/tdmfgi5/.imh/str_2019-07-30_11:43:10
>>> /opt/sharedrads/check_user tdmfgi5 --plaintext

#################################################################################
  INMOTION HOSTING  .:: SHARED RADS ::.  SHARED RESOURCE ABUSE DETECTION SCRIPTS
#################################################################################
                       Tue Jul 30 11:43:02 EDT 2019  

    Displaying today's most recent CPU usage data as recorded by process accounting 
       CPU minutes:  104.88cp (3.33%)          Actual time:  4110.51re (0.66%) 
        (since my last data poll @ 09:07 EDT tdmfgi5 burned another ~45 cp) 

  # of executions for CPU intensive processes that have been spawned by this user today 
php:  2732  perl:  0  imap:  443  pop3:  0  exim:  4  boxtrap:  0  ftp:  0  cron:  0  

CPU minutes used today         Historical CPU usage data      Most expensive processes 
12:00AM EDT :: 0.17cp		Jul 29 :: 159.18cp (1.00%)	php-cgi :: 47.11 secs
03:00AM EDT :: 8.09cp		Jul 28 :: 179.38cp (2.97%)	php-cgi :: 47.10 secs
06:00AM EDT :: 43.5cp		Jul 27 :: 189.94cp (3.12%)	php-cgi :: 46.99 secs
09:00AM EDT :: 59.9cp		Jul 26 :: 246.93cp (3.69%)	php-cgi :: 46.85 secs
 (no data available)		Jul 25 :: 229.35cp (3.60%)	php-cgi :: 46.75 secs
 (no data available)		Jul 24 :: 209.50cp (2.68%)	php-cgi :: 45.22 secs
 (no data available)		Jul 23 :: 222.95cp (2.96%)	php-cgi :: 42.89 secs
 (no data available)		Jul 22 :: 199.23cp (3.24%)	php-cgi :: 39.55 secs

  Displaying top utilization processes for user as recorded by cPanel and dcpumon 
  Top Process  %CPU 111  /opt/php56/bin/php-cgi /home/tdmfgi5/public_html/tdmfginc.com/index.php  
  Top Process  %CPU 95.2  /opt/php56/bin/php-cgi /home/tdmfgi5/public_html/tdmfginc.com/wp-admin/admin-ajax.php  
  Top Process  %CPU 93.9  /opt/php56/bin/php-cgi /home/tdmfgi5/public_html/ipsumseo.com/wp-admin/admin-ajax.php  


 RADS has detected these custom cron jobs currently enabled for this account 
SHELL="/bin/bash"
* * * * * cd /home/tdmfgi5/public_html; php /home/tdmfgi5/public_html/cron.php > /dev/null
2 23 * * 0 /usr/local/bin/imap-archiver -p -q








      USER    QUERIES       TIME   LOCKTIME   ROWSSENT  ROWSRECVD

  ERROR: Could not locate any bandwidth data for tdmfgi5 in /var/cpanel/bandwidth/   



>>> /opt/sharedrads/nlp tdmfgi5 -p -w 80 --today
Using /var/log/apache2/domlogs/tdmfgi5/pur-tungsten.tdmfginc.com-ssl_log

-Hourly hits (30/Jul/2019)------------------------------------------------------
08: 927   09: 413   10: 1029  11: 401   

-HTTP response codes------------------------------------------------------------
200: 2173  301: 5     302: 39    304: 504   403: 1     404: 42    405: 1     
406: 4     503: 1     

-Duplicate requests + response codes--------------------------------------------
265   200   POST /wp-admin/admin-ajax.php
54    200   GET /
49    200   POST /?wc-ajax=get_refreshed_fragments
33    200   GET /s/842c8f.js
32    200   GET /s/68e3d4.js
32    200   GET /s/8c8471.js
31    200   GET /wp-content/plugins/file-manager-advanced/application/assets/ico
30    404   GET /2015/11/02/hello-world/
29    200   GET /wp-content/uploads/2017/12/pt-original-logo2-u32558.png
29    200   GET /wp-content/uploads/2019/07/NSSM.png

-Requests for non-static content------------------------------------------------
265   200   POST /wp-admin/admin-ajax.php
185   200   POST /wp-cron.php
112   200   GET /
67    200   POST /
31    404   GET /2015/11/02/hello-world/
29    200   GET /wp-admin/load-styles.php
25    200   GET /wp-admin/admin.php
25    200   GET /wp-login.php
24    200   GET /wp-content/plugins/live-composer-page-builder/css/font/fontawes
21    200   GET /wp-admin/admin-ajax.php

-Top user agents----------------------------------------------------------------
1129   "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:68.0) Gecko/20100101 Fir
234    "'Mozilla/5.0 (compatible; DuckDuckBot-Https/1.1; https://duckduckgo.com/
230    "Mozilla/5.0 (iPhone; CPU iPhone OS 12_3_1 like Mac OS X) AppleWebKit/605
185    "WordPress/4.9.10; https://pur-tungsten.com"
177    "Mozilla/5.0 (Linux; Android 9; SAMSUNG SM-G965U Build/PPR1.180610.011) A
92     "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik
67     "Mozilla/5.0 (Linux; Android 9; SM-N960U) AppleWebKit/537.36 (KHTML, like
64     "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik
53     "Mozilla/5.0 (iPad; CPU OS 12_3_1 like Mac OS X) AppleWebKit/605.1.15 (KH
51     "Mozilla/5.0 (Linux; Android 6.0.1; SAMSUNG-SM-G870A) AppleWebKit/537.36

-Top IPs with PTR records-------------------------------------------------------
1129   76.124.35.212     c-76-124-35-212.hsd1.pa.comcast.net.
235    50.16.241.117     ec2-50-16-241-117.compute-1.amazonaws.com.
185    144.208.76.152    ecld208.inmotionhosting.com.
177    96.4.86.147       static-147-86-4-96.hawkins.tn.ena.net.
92     76.8.207.90       No Record Found
79     174.17.18.22      174-17-18-22.phnx.qwest.net.
68     216.150.106.177   ear-rural-dsl-176.earlsboro.ok.mbo.net.
61     161.97.250.102    Resolver Error
54     172.243.231.16    Query Timed Out
51     174.87.216.41     174-087-216-041.dhcp.chtrptr.net.


>>> /opt/sharedrads/recent-cp tdmfgi5 -b

+-----------+------------------+------------------+------------------+------------------+
|  command  |        1m        |        5m        |       15m        |       60m        |
+-----------+------------------+------------------+------------------+------------------+
| rm        |     0.00s   0.0% |     0.00s   0.0% |     0.00s   0.0% |     0.00s   0.0% |
| sendmail  |     0.00s   0.0% |     0.00s   0.0% |     0.00s   0.0% |     0.00s   0.0% |
| cat       |     0.00s   0.0% |     0.00s   0.0% |     0.00s   0.0% |     0.00s   0.0% |
| exim      |     0.00s   0.0% |     0.00s   0.0% |     0.00s   0.0% |     0.00s   0.0% |
| proxyexec |     0.00s   0.0% |     0.00s   0.0% |     0.00s   0.0% |     0.00s   0.0% |
| webmaild  |     0.00s   0.0% |     0.00s   0.0% |     0.05s   0.0% |     0.46s   0.0% |
| whoami    |     0.00s   0.0% |     0.00s   0.0% |     0.00s   0.0% |     0.00s   0.0% |
| pop3      |     0.00s   0.0% |     0.00s   0.0% |     1.17s   0.8% |     3.80s   0.2% |
| bash      |     0.00s   0.9% |     0.01s   0.0% |     0.02s   0.0% |     0.06s   0.0% |
| imap      |     0.00s   0.0% |     0.37s   1.1% |     1.81s   1.3% |     5.03s   0.3% |
| php-cgi   |     0.11s  99.1% |    32.80s  98.9% |   135.77s  97.8% |  1879.04s  99.5% |
+-----------+------------------+------------------+------------------+------------------+
| total     |     0.11s 100.0% |    33.18s 100.0% |   138.81s 100.0% |  1888.40s 100.0% |
+-----------+------------------+------------------+------------------+------------------+
s = processs user time in cpu seconds, cp = user time + system time in cpu minutes


>>> Running processes prior to suspension
USER        PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND
tdmfgi5    2181  0.0  0.0  84508  4664 ?        S    11:42   0:00 dovecot/imap
tdmfgi5   30415  0.0  0.0  84988  5716 ?        S    09:51   0:00 dovecot/imap
tdmfgi5   34159  0.0  0.0  84844  5336 ?        S    11:10   0:00 dovecot/imap
tdmfgi5   99831  0.0  0.0  84908  5716 ?        S    11:22   0:00 dovecot/imap
tdmfgi5  123620  0.0  0.0  85228  5828 ?        S    10:49   0:00 dovecot/imap
tdmfgi5  145812  0.0  0.0  85080  5824 ?        S    11:31   0:00 dovecot/imap
tdmfgi5  170084  0.0  0.0  85228  5720 ?        S    11:36   0:00 dovecot/imap
tdmfgi5  178764  0.0  0.0  85788  6532 ?        S    10:21   0:00 dovecot/imap
tdmfgi5  181675  0.0  0.0  85200  5824 ?        S    11:38   0:00 dovecot/imap
tdmfgi5  181677  0.0  0.0  85196  5192 ?        S    11:38   0:00 dovecot/imap
tdmfgi5  184017  0.0  0.0  88516  6060 ?        S    11:39   0:00 dovecot/imap
tdmfgi5  186274  0.0  0.0  85192  5440 ?        S    11:39   0:00 dovecot/imap
tdmfgi5  193881  0.0  0.0 116416 26388 ?        S    11:41   0:00 webmaild - serving 76.124.35.212
Page not found – T&D Advanced Radiation Shielding

T&D Advanced Radiation Shielding

It looks like nothing was found at this location.