See https://www.anomali.com/blog/multiple-chinese-threat-groups-exploiting-cve-2018-0798-equation-editor-vulnerability-since-late-2018 Check the samples exploiting CVE-2018-0798 and which CLSIDs/class names they use, update clsid and rtfobj accordingly.