AWS GuardDuty False Positive on OpenDSN IP

According to reports from Cycle customers, sometime after 3 pm EST today, the service AWS GuardDuty started to flag DNS traffic from Cycle servers to Cisco's OpenDNS resolver (208.67.222.222) as botnet command and control activity.

This report is a false positive and nothing on your infrastructure is pointing to a compromise based on this specific event in GuardDuty.

What You're Likely Seeing

What's being reported is a high-severity alert for something that looks like this.

  • Type - Backdoor:EC2/C&CActivity.B
  • Threat List - Amazon Active Threat Defense
  • Threat Name - suspicious:cmdctrl/botnet
  • Remote IP - 208.67.222.222 (TCP/53)

Why Cycle talks to that IP

The discovery service in the environments use upstream resolvers for egress traffic:

  • 8.8.8.8 / 8.8.4.4 - Google
  • 1.1.1.1 / 1.0.0.1 - Cloudflare
  • 9.9.9.9 - Quad9
  • 208.67.222.222 - Cisco OpenDNS


These providers are deliberately rotated across.

We are confident this is a false positive due to the IP thats flagged being a trusted OpenDNS endpoint provided by Cisco. It is absolutely not botnet infrastructure.


Christopher Aubuchon...
  • Brandon Cummings...

    This happened to us around 330pm ET - AWS GuardDuty started alerting of critical 8 and 9 alerts.

  • Jake Warner...

    Looks like these reports only happened for 30-45 min overall. AWS must've accidentally added the IP before removing it.

Join the conversation

Sign in with your Cycle account to reply to this thread.

v2026.08.26.01 · © 2026 Petrichor Holdings, Inc.
Cookies

Cookies Preferences

We run basic, anonymous analytics by default to measure site traffic. By clicking "Accept," you allow additional cookies for advanced app improvements and tailored advertising. Choose what you share by clicking "Customize."