https://blog.shodan.io/its-still-the-data-stupid/
You can search for Redis instances that have disabled authentication and have a "crackit" key stored in them which is created by one of those Redis malware bots:
https://beta.shodan.io/search?query=crackit
I'll add that the vendors have actually gotten much better! Redis and MongoDB both now have good, secure defaults. And I believe both will throw you a huge warning if you're listening on 0.0.0.0 w/out authentication.
Favicons can be a single image or multiple images.
Here is a good recent thread on it on HN. Will put the map there as well come to think of it.
https://beta.shodan.io/search?query=http.favicon.hash%3A7085...
It takes a bit more refining to get a good list of results; the general idea is to find websites that look like the real deal but are located somewhere on the Internet where you didn't expect to find them.
I keep meaning to sit down and do a bit of analysis on the source of the connections.