nerdexam
GIAC

GCIH · Question #466

You are a member of your organization's IT Security Team. The following were found in the hosts file on a Windows workstation that is on your network. The system administrator thought these were…

The correct answer is C. 1. Entries in the hosts file that map domain names to the local loopback address (127.0.0.1) are often entered by malware to prevent users from accessing well known anti-virus web sites after the computer has been infected. #102.54.94.97 is a sample entry in a Windows 7 hosts…

Malware Analysis & Advanced Persistent Threats

Question

You are a member of your organization's IT Security Team. The following were found in the hosts file on a Windows workstation that is on your network. The system administrator thought these were 'interesting' snippers from the hosts file. Which of the entries listed below are cause for further investigation?

Exhibit

GCIH question #466 exhibit

Options

  • A4
  • B3
  • C1
  • D2

How the community answered

(16 responses)
  • A
    6% (1)
  • B
    6% (1)
  • C
    88% (14)

Explanation

Entries in the hosts file that map domain names to the local loopback address (127.0.0.1) are often entered by malware to prevent users from accessing well known anti-virus web sites after the computer has been infected. #102.54.94.97 is a sample entry in a Windows 7 hosts file, while 127.0.0.1, 0.0.0.0, and ::1 are default entries in a Windows 7 hosts file.

Topics

#hosts file modification#DNS hijacking#malware indicators#Windows forensics

Community Discussion

No community discussion yet for this question.

Full GCIH Practice