> Source: [sk121097](https://support.checkpoint.com/results/sk/sk121097)

# sk121097 - Threat Emulation is not scanning files if their extension was changed on the server side

| Property | Value |
|----------|-------|
| Solution ID | sk121097 |
| Date Created | 2017-10-24 |
| Last Modified | 2017-10-25 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Threat Emulation is not scanning files if their extension was changed to unsupported file type, for example:  
  **Original file:** *xxx.pdf*   
  **Changed file:** *xxx_pdf.png*
* The HTTP GET request for the file *(xxx_pdf.png)* are answered with Content-Type HTTP header as *Content-Type: image/png* ***or*** as the relevant file type.
* The original file is blocked (.pdf) as malicious, when it is sent using the original extension.

## Cause

Once the extension is being changed to one of not interesting extensions, it will not be emulated as it will not cause harm to the receiving system unless the user will cooperate with the attacker and will change the extension back.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
