The fake pdf attached to the "PURCHASE ORDER 05-30-2023" email contains a link, from which you download a tgz file with a TAR, inside which there is an exe: the malware.
Cybercrime, a fake email from the Philippines conveys Formbook

Malware Hunter JAMESWT Technical Analysis
A fake email from the Philippines conveys Formbook. The r00 attachment contains an exe file: the malware itself
“Re: VERY URGENT Re: PI # 2320” is the subject of a false e-mail from a company in the Philippines that is broadcasting a new Formbook campaign.
R00 attachment contains an exe file: the malware itself. Formbook, through the keylogger function, is able to acquire everything the user types. It can also steal email and browser credentials, as well as take screenshots. Finally, it has the ability to remotely issue commands on the infected PC, such as downloading additional payloads or updating those present.