# Possibly incorrect domain for ET ADWARE\_PUP signature

**URL:** <https://community.emergingthreats.net/t/possibly-incorrect-domain-for-et-adware-pup-signature/3211>\
**Category:** Rule Signatures\
**Tags:** suricata\
**Created:** [February 24, 2026, 10:59am UTC](https://community.emergingthreats.net/t/possibly-incorrect-domain-for-et-adware-pup-signature/3211 "2026-02-24T10:59:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![starbuck](https://avatars.discourse-cdn.com/v4/letter/s/9dc877/32.png) [@starbuck](https://community.emergingthreats.net/u/starbuck)\
**Post date:** [February 24, 2026, 10:59am UTC](https://community.emergingthreats.net/t/possibly-incorrect-domain-for-et-adware-pup-signature/3211/1 "2026-02-24T10:59:30Z")

</div>

Hiya,

our team received an alert for the signature `ET ADWARE_PUP Observed DNS Query to Passive Income App Domain (honeybook .com)` which when I looked at the signature for contains the following:

```auto
alert dns $HOME_NET any -> any any (msg:"ET ADWARE_PUP Observed DNS Query to Passive Income App Domain (honeybook .com)";
dns.query;
dotprefix;
content:".honeybook.com";
nocase;
endswith;
classtype:pup-activity;
sid:2067483;
rev:1;
metadata:attack_target Client_Endpoint, created_at 2026_02_11, deployment Perimeter, malware_family PUP, confidence High, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2026_02_11;)

```

From researching, `honeybook[.]com` looks to be a CRM tool, and the actual passive income tool is called `honeygain[.]com`

Screenshot below attempts to show this a bit better

 ![Screenshot 2026-02-24 at 10.41.37](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/2X/7/700742599ec2ac9f60c32d22528ec7ddda3a1980.png)

Just wanted to mention this incase it is the incorrect domain and needs to be tweaked 🙏

---

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [February 24, 2026, 4:04pm UTC](https://community.emergingthreats.net/t/possibly-incorrect-domain-for-et-adware-pup-signature/3211/2 "2026-02-24T16:04:32Z")

</div>

Hey @starbuck

Thanks for the detailed analysis! These are false positives and the rules should be removed within the next 30 mins or so.

Apologies for the noise!  
Isaac

---

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [February 25, 2026, 8:11pm UTC](https://community.emergingthreats.net/t/possibly-incorrect-domain-for-et-adware-pup-signature/3211/3 "2026-02-25T20:11:20Z")

</div>

Thanks @starbuck @ishaughnessy !
