It depends. Files with multiple extensions such as .php.jpg or .jpg.php will also be scanned by default since the default setting for “Scan files with double extensions” is Yes.
In fact, they should be scanned. Remember that AcyMailing had a massive security issue from April 2023 to September 2023 which allowed anyone to upload arbitrary files. The most common exploit was to upload fake image files with double extensions which were, in fact, malicious hacking scripts. Admin Tools' .htaccess Maker's Frontend and Backend Protection features would prevent them from running and causing harm to your site, but the files would still pile up.
Is it possible that you had AcyMailing installed and the files you see come from its security issue?
Nicholas K. Dionysopoulos
Lead Developer and Director
🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!