Detection of Unauthorized Windows Hosts File Access
Anomalous processes accessing the Windows hosts file are often indicative of malware like BlankGrabber Stealer or Gh0st RAT attempting to perform traffic redirection or DNS spoofing.
Monitoring access to the Windows hosts file (C:\Windows\System32\drivers\etc\hosts) is critical for detecting malicious activity aimed at subverting DNS resolution. Threat actors utilize this file to redirect victim traffic to attacker-controlled infrastructure, serve malicious content, or block connectivity to security update services and remediation websites. This behavior is a common post-infection artifact observed in various malware families, including BlankGrabber Stealer and Gh0st RAT. Defenders should focus on processes that interact with the hosts file outside of expected system maintenance or browser operations, as these interactions often signify an attempt to maintain persistence or conduct man-in-the-middle attacks.
Attack Chain
- Initial malware execution on a Windows endpoint.
- Malware establishes persistence or gains elevated privileges via local exploits or social engineering.
- Malware identifies the target system's DNS configuration.
- The process opens a file handle to the Windows hosts file at C:\Windows\System32\drivers\etc\hosts.
- The attacker injects malicious entries into the hosts file to map legitimate domain names to unauthorized IP addresses.
- The operating system performs DNS resolution using the modified hosts file for subsequent network requests.
- The user or system is transparently redirected to attacker-controlled domains or blocked from accessing security resources.
Impact
Successful modification of the hosts file allows an attacker to intercept or manipulate network traffic, bypass security controls, and compromise the integrity of the victim's DNS resolution. This can lead to credential theft, deployment of secondary payloads, and persistent C2 communication, affecting the security posture of the targeted endpoint.
Recommendation
Prioritize the implementation of object access auditing to monitor for unauthorized modifications to critical configuration files.
- Enable "Audit Object Access" in Group Policy for Windows Security Event Log 4663 to capture interactions with the hosts file.
- Deploy the provided Sigma rule to your SIEM to identify non-standard processes attempting to access the hosts file.
- Investigate any alerts generated by the detection, verifying the legitimacy of the parent process and the intent of the file access.
- Tune the detection logic by adding known administrative or security tools to the exclusion list to minimize false positives.
Immediate actions
Enable Audit Object Access (4663) for the hosts file on critical servers
Deploy the Sigma detection rule to the SIEM
Mitigations
Review and restrict write access to the hosts file to authorized system accounts only
Unauthorized traffic redirection TTP
Detection coverage 1
Detect Unauthorized Access to Windows Hosts File
mediumDetects non-system and non-browser processes attempting to access the Windows hosts file, which is a common technique for traffic redirection and DNS spoofing.
Detection queries are available on the platform. Get full rules →