I updated oledump to handle a new type of malicious document: an XML file, not with VBA macros, but with an embedded OLE object that is a VBS file.
more here............http://blog.didierstevens.com/2015/03/27/oledump-and-xml-with-embedded-ole-object/
more here............http://blog.didierstevens.com/2015/03/27/oledump-and-xml-with-embedded-ole-object/