Security researchers highlighted favicon hashing as a practical way to uncover malicious web infrastructure, showing that the small icon files used by websites can act as reusable fingerprints for phishing pages, command-and-control panels, and exposed directories. SANS demonstrated the technique by calculating the MurmurHash of Microsoft’s favicon and querying Shodan for matching sites, then narrowing results with page text and hosting filters to identify fake Microsoft login portals used for credential theft.
Additional research expanded the method beyond single-brand phishing to broader infrastructure hunting. SentinelOne described tracking reused web artifacts such as favicons, trackers, outgoing links, and downloaded files to uncover fake AWS and USPS-themed phishing sites as well as Kimsuky-linked infrastructure, while a separate threat hunting note compiled favicon hashes tied to numerous malware families, C2 frameworks, and criminal web panels. Together, the reports show that defenders can use favicon-based searches and related network indicators to find phishing domains, exposed attacker tooling, and malware control servers at low cost.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
SentinelOne references a May 2023 campaign in which the North Korean-attributed actor Kimsuky evolved reconnaissance capabilities in a global operation using a malware component called ReconShark.
A USPS-themed phishing campaign reused Yandex Tracker ID 93030690 in tracking.php files across multiple phishing sites to collect victims' financial details. SentinelOne says this reuse linked infrastructure observed from April to July 2023.
A February 2023 campaign targeted cloud service credentials by impersonating AWS login pages and distributing phishing through emails and non-Google ads. SentinelOne describes detection logic based on reused AWS-related favicons and links to the legitimate AWS sign-in page.
A ReverseTheMalware blog post compiled favicon hashes for numerous malware families, C2 frameworks, and criminal web panels to support discovery of malicious infrastructure, including Mythic C2, Covenant, Amadey, Matanbuchus, and RisePro.
SentinelOne published guidance on tracking brand-impersonation infrastructure using VirusTotal NetIoc and reused artifacts such as favicons, trackers, outgoing links, and downloaded files. The article included examples tied to AWS phishing, USPS-themed phishing, and Kimsuky infrastructure.
A SANS ISC article states that Shodan added favicon-hash searching to help identify phishing kits, enabling defenders to search infrastructure by MurmurHash values of HTTP favicons.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 32 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
reversethemalware.blogspot.com
Open sourcesentinelone.com
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.