I am currently experiencing some problems with my server. Load used to be very good, at peak times it being just 0.6 or so.
Now the load is currently 3-10 and is a bit all over the place.
When looking at current cpu usage, I cant se any particular process which is using a lot of cpu or memory:
Things in Top also look normal, cpu usage at 7%. A quick restart of Apache brings the load down, however I cant see that its using any excessive amount of CPU Or Memory. Could this be a possible attack?
Code:Pid Owner Priority Cpu % Mem % Command 21471 nobody 0 1.6 1.6 /usr/local/apache/bin/httpd -DSSL 21474 nobody 0 1.6 1.6 /usr/local/apache/bin/httpd -DSSL 21472 nobody 0 1.3 1.6 /usr/local/apache/bin/httpd -DSSL 21483 nobody 0 1.3 1.6 /usr/local/apache/bin/httpd -DSSL 21488 nobody 0 1.3 1.7 /usr/local/apache/bin/httpd -DSSL 22029 root 0 0.7 0.1 top -n 2 -b -c 17531 root 0 0.3 0.2 ./sc_serv config11.conf 1 root 0 0.0 0.1 init [3] 2 root 19 0.0 0.0 [ksoftirqd/0] 28 root 0 0.0 0.0 [pdflush] 29 root 0 0.0 0.0 [pdflush] 19 root 0 0.0 0.0 [khubd] 30 root 0 0.0 0.0 [kswapd0] 105 root 0 0.0 0.0 [kseriod] 173 root 0 0.0 0.0 [kjournald] 1008 root 0 0.0 0.0 [shpchpd_event] 1316 root 0 0.0 0.0 [kjournald] 1858 root 0 0.0 0.1 syslogd -m 0 1862 root 0 0.0 0.0 klogd -x 1896 root 0 0.0 0.1 rpc.idmapd 1963 root 0 0.0 0.1 /usr/sbin/smartd 1972 root 0 0.0 0.0 /usr/sbin/acpid 3807 named 0 0.0 0.3 /usr/sbin/named -u named -t /var/named/chroot 3850 root 0 0.0 0.1 /usr/sbin/sshd 3863 root 0 0.0 0.1 xinetd -stayalive -pidfile /var/run/xinetd.pid 3964 root 0 0.0 1.0 /usr/sbin/clamd 3970 mailnull 0 0.0 0.2 /usr/sbin/exim -bd -q60m 3975 mailnull 0 0.0 0.1 /usr/sbin/exim -tls-on-connect -bd -oX 465 3980 root 0 0.0 0.1 antirelayd 4017 root 0 0.0 0.1 crond 4144 root 0 0.0 0.3 cpsrvd - waiting for connections 4149 root 19 0.0 0.7 cpanellogd - setting up logs for bujingai 4211 cpanel 0 0.0 0.1 /usr/bin/stunnel-4.04local /usr/local/cpanel/etc/stunnel/default/stunnel.conf.run 4229 root 0 0.0 0.4 cppop - accepting on port 110 4277 root 0 0.0 0.1 pure-ftpd (SERVER) 4280 root 0 0.0 0.1 /usr/sbin/pure-authd -s /var/run/ftpd.sock -r /usr/sbin/pureauth 4334 mailman 0 0.0 0.1 /usr/bin/python /usr/local/cpanel/3rdparty/mailman/bin/mailmanctl -s start 4342 mailman 0 0.0 0.2 /usr/bin/python /usr/local/cpanel/3rdparty/mailman/bin/qrunner --runner=ArchRunner:0:1 -s 4343 mailman 0 0.0 0.2 /usr/bin/python /usr/local/cpanel/3rdparty/mailman/bin/qrunner --runner=BounceRunner:0:1 -s 4344 mailman 0 0.0 0.2 /usr/bin/python /usr/local/cpanel/3rdparty/mailman/bin/qrunner --runner=CommandRunner:0:1 -s 4345 mailman 0 0.0 0.2 /usr/bin/python /usr/local/cpanel/3rdparty/mailman/bin/qrunner --runner=IncomingRunner:0:1 -s 4346 mailman 0 0.0 0.2 /usr/bin/python /usr/local/cpanel/3rdparty/mailman/bin/qrunner --runner=NewsRunner:0:1 -s 4347 mailman 0 0.0 0.2 /usr/bin/python /usr/local/cpanel/3rdparty/mailman/bin/qrunner --runner=OutgoingRunner:0:1 -s 4348 mailman 0 0.0 0.2 /usr/bin/python /usr/local/cpanel/3rdparty/mailman/bin/qrunner --runner=VirginRunner:0:1 -s 4349 mailman 0 0.0 0.2 /usr/bin/python /usr/local/cpanel/3rdparty/mailman/bin/qrunner --runner=RetryRunner:0:1 -s 4353 dbus 0 0.0 0.1 dbus-daemon-1 --system 4368 root 0 0.0 0.2 hald 4394 root 0 0.0 0.0 /usr/sbin/portsentry -tcp 4433 root 0 0.0 0.0 /sbin/mingetty tty1 4434 root 0 0.0 0.0 /sbin/mingetty tty2 4435 root 0 0.0 0.0 /sbin/mingetty tty3 4436 root 0 0.0 0.0 /sbin/mingetty tty4 4437 root 0 0.0 0.0 /sbin/mingetty tty5 4438 root 0 0.0 0.0 /sbin/mingetty tty6 4826 root 0 0.0 0.1 /bin/sh /usr/bin/mysqld_safe --datadir=/var/lib/mysql --pid-file=/var/lib/mysql/Serv1.3Qhost.net.pid 4850 mysql 0 0.0 1.2 /usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --pid-file=/var/lib/mysql/Serv1.3Qhost.net.pid --skip-locking 4863 mysql 0 0.0 1.2 /usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --pid-file=/var/lib/mysql/Serv1.3Qhost.net.pid --skip-locking 4864 mysql 0 0.0 1.2 /usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --pid-file=/var/lib/mysql/Serv1.3Qhost.net.pid --skip-locking 4902 mysql 0 0.0 1.2 /usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --pid-file=/var/lib/mysql/Serv1.3Qhost.net.pid --skip-locking 5029 root 0 0.0 0.8 /usr/bin/spamd -d --allowed-ips=127.0.0.1 --pidfile=/var/run/spamd.pid --max-children=5 5044 root 0 0.0 2.0 spamd child 5045 root 0 0.0 1.7 spamd child 5483 mysql 0 0.0 1.2 /usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --pid-file=/var/lib/mysql/Serv1.3Qhost.net.pid --skip-locking 5702 jcoenen 0 0.0 0.1 imapd 5746 mysql 0 0.0 1.2 /usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --pid-file=/var/lib/mysql/Serv1.3Qhost.net.pid --skip-locking 5750 mysql 0 0.0 1.2 /usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --pid-file=/var/lib/mysql/Serv1.3Qhost.net.pid --skip-locking 6336 mailnull 0 0.0 0.1 /usr/sbin/exim -oX 26 -bd 6388 mysql 0 0.0 1.2 /usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --pid-file=/var/lib/mysql/Serv1.3Qhost.net.pid --skip-locking 6394 mailnull 0 0.0 0.2 /usr/bin/perl /usr/local/cpanel/bin/eximstats 6439 mysql 0 0.0 1.2 /usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --pid-file=/var/lib/mysql/Serv1.3Qhost.net.pid --skip-locking 6489 root 0 0.0 0.2 chkservd 8039 root 0 0.0 0.1 ./ventrilo_srv 15292 mysql 0 0.0 1.2 /usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --pid-file=/var/lib/mysql/Serv1.3Qhost.net.pid --skip-locking 17218 root 19 0.0 0.2 ./server_linux 17219 root 0 0.0 0.2 ./server_linux 17220 root 0 0.0 0.2 ./server_linux 17221 root 0 0.0 0.2 ./server_linux 17222 root 0 0.0 0.2 ./server_linux 17223 root 0 0.0 0.2 ./server_linux 17224 root 0 0.0 0.2 ./server_linux 17225 root 0 0.0 0.2 ./server_linux 17226 root 0 0.0 0.2 ./server_linux 17227 root 0 0.0 0.2 ./server_linux 17228 root 0 0.0 0.2 ./server_linux 17229 root 0 0.0 0.2 ./server_linux 17339 root 0 0.0 0.2 ./sc_serv config1.conf 17478 root 0 0.0 0.2 ./sc_serv config10.conf 18389 root 0 0.0 0.2 ./sc_serv config15.conf 18435 root 0 0.0 0.2 ./sc_serv config2.conf 18479 root 0 0.0 0.2 ./sc_serv config21.conf 18523 root 0 0.0 0.2 ./sc_serv config20.conf 19203 root 0 0.0 0.2 ./sc_serv config3.conf 19250 root 0 0.0 0.2 ./sc_serv config5.conf 19302 root 0 0.0 0.2 ./sc_serv config6.conf 19346 root 0 0.0 0.2 ./sc_serv config7.conf 19438 root 0 0.0 0.2 ./sc_serv config8.conf 19977 root 0 0.0 0.2 ./sc_serv econfig1.conf 20020 root 0 0.0 0.2 ./sc_serv econfig2.conf 20028 qhostnet 0 0.0 0.1 pure-ftpd (IDLE) 20124 root 0 0.0 0.2 ./sc_serv econfig3.conf 20277 root 0 0.0 0.2 ./sc_serv econfig4.conf 20364 root 0 0.0 0.2 ./sc_serv econfig5.conf 20394 khalij 0 0.0 0.2 pure-ftpd (IDLE) 20412 mitch 0 0.0 0.1 pure-ftpd (IDLE) 20460 root 0 0.0 0.2 ./sc_serv econfig6.conf 21382 bujingai 19 0.0 0.7 cpanellogd - http logs for bujingai 21383 bujingai 19 0.0 0.0 /usr/local/cpanel/bin/logrunner 1.0 /usr/local/cpanel/3rdparty/bin/english/webalizer -N 10 -D /home/bujingai/tmp/webalizer/dns_cache.db -R 250 -p -n bujingai.monkeybum.net -o /home/bujingai/tmp/webalizer /usr/local/apache/domlogs/bujingai.monkeybum.net 21384 bujingai 19 0.0 0.0 /usr/local/cpanel/3rdparty/bin/english/webalizer -N 10 -D /home/bujingai/tmp/webalizer/dns_cache.db -R 250 -p -n bujingai.monkeybum.net -o /home/bujingai/tmp/webalizer /usr/local/apache/domlogs/bujingai.monkeybum.net 21464 root 0 0.0 1.4 /usr/local/apache/bin/httpd -DSSL 21470 root 0 0.0 0.3 /usr/bin/perl /usr/local/cpanel/bin/leechprotect 21473 nobody 0 0.0 1.6 /usr/local/apache/bin/httpd -DSSL 21475 nobody 0 0.0 1.6 /usr/local/apache/bin/httpd -DSSL 21477 nobody 0 0.0 1.6 /usr/local/apache/bin/httpd -DSSL 21490 nobody 0 0.0 1.6 /usr/local/apache/bin/httpd -DSSL 21510 nobody 0 0.0 1.6 /usr/local/apache/bin/httpd -DSSL 21602 mitch 0 0.0 0.1 pure-ftpd (IDLE) 21613 root 0 0.0 0.1 crond 21617 qhostnet 0 0.0 0.1 wget -q -O /dev/null http://pheonixhosting.co.uk/Cowtoon/socket.php 22007 nobody 0 0.0 1.5 /usr/local/apache/bin/httpd -DSSL 22018 root 0 0.0 0.5 whostmgrd - serving 86.137.110.158 22019 nobody 0 0.0 1.5 /usr/local/apache/bin/httpd -DSSL 22020 root 0 0.0 2.1 /usr/local/cpanel/whostmgr/bin/whostmgr2 ./top 22022 root 0 0.0 0.5 whostmgrd - serving 86.137.110.158 22023 root 0 0.0 0.5 whostmgrd - serving 86.137.110.158


LinkBack URL
About LinkBacks
Reply With Quote