Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298 — SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough | Kitploit
Tools/GitHubGitHub/abc1230940/soc336-windows-ole-zero-click-rce-exploitation-detected-cve-2025-21298
Vulnerability AnalysisExploitationLateral MovementReverse EngineeringForensicsPhishingMalware AnalysisCommand and ControlThreat Intelligence
Learning & Education
Incident Response
Email Security
GitHubabc1230940/soc336-windows-ole-zero-click-rce-exploitation-detected-cve-2025-21298

SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

View RepositoryWebsite
224 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

LinkedIn Gmail Instagram Old Discord Reddit


SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

phishing email

🔎 Table of Content
  1. Situation
  2. Alert Overview
  3. Tools Used
  4. Analysis
    • Email Security
    • Log Management
      • Proxy Log
    • Endpoint Security
      • Terminal History
      • Network Action
      • Processes
      • CVE-2025-21298
  5. Playbook
  6. Analyst Note
  7. Reference

(Back to Top)

Situation

One of our employees Austin received a phishing email from a suspicious sender and an alert was triggered after he opened the email using Outlook At Feb, 04, 2025, 04:18 PM. The trigger reason was "Malicious RTF attachment identified with known CVE-2025-21298 exploit pattern" .

(Back to Top)

Alert Overview

image

EventID : 314

Event Time : Feb, 04, 2025, 04:18 PM (I think it was wrong)

Rule : SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298)

Level : Security Analyst

SMTP Address : 84.38.130.118

Source Address : [email protected]

Destination Address : [email protected]

E-mail Subject : Important: Action Required for Upcoming Project Deadline

Attachment : mail.rtf

Attachment Hash : df993d037cdb77a435d6993a37e7750dbbb16b2df64916499845b56aa9194184

Device Action : Allowed

Trigger Reason : Malicious RTF attachment identified with known CVE-2025-21298 exploit pattern.

(Back to Top)

Tools Used

  1. VirusTotal
  2. AbuseIPDB
  3. Gemini

(Back to Top)

Analysis

Let's dig into the Email Security, Log Management and Endpoint Security Log for the alert triage.

Email Security

Screenshot 2026-05-27 151659

I searched the sender address projectmanagement@pm[.]me and clicked the email "Important: Action Required for Upcoming Project Deadline" sent at 05:12 AM on the same day, which was weird to me because the urgent tones and wordings like "Important" and "Action Required" gave me an insight of a phishing email.



Screenshot 2026-05-27 175944

I searched the domain pm[.]me on VirusTotal and only 1 vendor decided it as suspcious.



Screenshot 2026-05-27 151915

However, when I searched the SMTP Address 84[.]38[.]130[.]118, 7 vendors flagged it as Malicious and Malware and it was related to SILVER C2 server.



Screenshot 2026-05-27 180753 Screenshot 2026-05-27 180810

84[.]38[.]130[.]118 was also found in AbuseIPDB database. It locates at Riga, Riga, Latvia, belongs to the domain name rixhost.lv and categorized as DDoS Attack, Hacking and Exploited Host.



Screenshot 2026-05-27 152243

Finally I searched the hash df993d037cdb77a435d6993a37e7750dbbb16b2df64916499845b56aa9194184 of the attachment mail.rtf on VirusTotal and 29 out of 61 vendors flagged the attachment as Malicious. It belongs to the malware family rtfmalformb and it was associated with the vulnerability CVE-2025-21298.

It was confirmed that a phishing email with a malicious attachment was sent to Austin.

(Back to Top)

Download Tool