The fake pdf attached to the "PURCHASE ORDER 05-30-2023" email contains a link, from which you download a tgz file with a TAR, inside which there is an exe: the malware.
Cybercrime, “Purchase Order – PO.No.660240685” carries STRRAT via RATDispenser

“Purchase Order – PO.No.660240685” conveys STRRAT via RATDispenser. The compressed attachment contains a JS, which runs the loader. The latter, however, installs the final malware
“Purchase Order – PO.No.660240685” is the subject of a fake email from Poland which carries STRRAT via RATDispenser.
The compressed attachment contains a JS, which runs the loader. The latter, however, installs the final malware. STRRAT, aka STRATION and WAREZOV, is a family of worms that propagate using email. The goal is to create a zombie network that can be exploited to send spam or other malicious payloads.