An analyst reviewing a Windows workstation finds that the file C:\Windows\System32\drivers\etc\hosts has been modified and now contains several entries mapping well-known banking domains to 127.0.0.1. The file's LastWriteTime is two days ago, and no administrator has reported making the change. Which conclusion is MOST appropriate?
The hosts file is a common target for malware that redirects known domains to loopback or to attacker infrastructure to intercept or block traffic. Mapping banking domains to 127.0.0.1 is a classic pattern that prevents the real site from loading while potentially enabling credential theft via a local listener. The unexplained modification and recent timestamp justify immediate investigation.
Why this answer
Redirecting well-known banking domains to 127.0.0.1 through the hosts file is a recognized adversary technique for intercepting or blocking traffic, and the unexplained, recent modification makes it more suspicious. The appropriate response is to investigate the change, identify the process or account responsible, and examine the host for related indicators rather than dismissing it as routine or user-initiated.
Exam trap
The trap here is assuming any hosts-file edit is harmless user customization, when redirecting banking domains to loopback is a classic interception technique rather than ad-blocking.