AWS GuardDuty False Positive on OpenDSN IP
According to reports from Cycle customers, sometime after 3 pm EST today, the service AWS GuardDuty started to flag DNS traffic from Cycle servers to Cisco's OpenDNS resolver (208.67.222.222) as botnet command and control activity.
This report is a false positive and nothing on your infrastructure is pointing to a compromise based on this specific event in GuardDuty.
What You're Likely Seeing
What's being reported is a high-severity alert for something that looks like this.
- Type - Backdoor:EC2/C&CActivity.B
- Threat List - Amazon Active Threat Defense
- Threat Name - suspicious:cmdctrl/botnet
- Remote IP - 208.67.222.222 (TCP/53)
Why Cycle talks to that IP
The discovery service in the environments use upstream resolvers for egress traffic:
8.8.8.8/8.8.4.4- Google1.1.1.1/1.0.0.1- Cloudflare9.9.9.9- Quad9208.67.222.222- Cisco OpenDNS
These providers are deliberately rotated across.
We are confident this is a false positive due to the IP thats flagged being a trusted OpenDNS endpoint provided by Cisco. It is absolutely not botnet infrastructure.
- Brandon Cummings...
This happened to us around 330pm ET - AWS GuardDuty started alerting of critical 8 and 9 alerts.
- Jake Warner...
Looks like these reports only happened for 30-45 min overall. AWS must've accidentally added the IP before removing it.
Join the conversation
Sign in with your Cycle account to reply to this thread.