Malicious attachments are sent with specially crafted icons that are pretending to be real document files. In addition to this, they often use double extensions, such as pdf.pdf. or doc.exe, taking advantage of the fact that Windows by default hides the extension, so sometimes user wouldnt notice which file is the one it claims to be. The trick is cunning, because it hides the real extension even if the user has disabled the feature of extension hiding on Windows.”]
Source: https://blog.malwarebytes.com/cybercrime/2016/09/lesser-known-tricks-of-spoofing-extensions/

