---
title: "Favicon Impersonation"
slug: "favicon-impersonation"
updated: 2026-06-09T03:02:36Z
published: 2026-06-09T03:02:36Z
canonical: "help.silentpush.com/favicon-impersonation"
stale: true
---

> ## Documentation Index
> Fetch the complete documentation index at: https://help.silentpush.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Favicon Impersonation

## Favicon Impersonation Query

The Favicon Impersonation query identifies domains using a brand’s favicon without authorization to enhance the credibility of phishing or illegitimate domains.

#### Threat Actors use Favicons to:

- Increase the visual credibility of illegitimate domains.
- Enhance the realism of phishing attacks.
- Evade basic detection tools.
- Boost social engineering efforts.
- Maintain consistency across phishing domains.

### Execute a Favicon Impersonation Query

1. From the navigation menu, select **Reconnaissance > > Favicon Impersonation**.
2. Click **Create New +**.
3. In the **Domain Name** box, enter the domain to investigate.
4. Click **Search**.
5. (Optional) Click **Save** to store the results.

### Understand Favicon Impersonation Results

Results are displayed in a table with the following columns:

- **Scan Date**: Date and time of the scan.
- **Origin URL**: Originally scanned URL.
- **URL**: Final destination URL of the query.
- **Hostname**: Name of the domain.
- **Favicon Icons**: Image of the favicon.
- **Favicon Murmur3**: Murmur3 hash of the standard favicon.
- **Favicon2 Murmur3**: Murmur3 hash of an alternative favicon.

### Filter and Expand Results

1. Add or remove filters by selecting the icon next to B**asic Raw Data,** then choose preferences.
2. Select **Expand** on a result to view additional details.
