Lots of malware hides under bogus extensions. Here's how to find files with graphics extensions that are really executable files:

find / -regex ".*\.\(jpg\|gif\|png\|jpeg\)" -type f -exec file -p '{}' \; | grep ELF | cut -d":" -f1

@dl1mur4tdj that doesn't find she'll scripts masquerading as images though. Better to filter out the known good types and have it show anything unexpected
