Intercepting "hosts" file entries lookup

OK OK I do know it has nothing to do with Wireshark, but how would you intercept those kind of requests? If they get a reply you will never see a dns request packet, so how would you go deeper? Thanks