Hopefully this isn't too off topic, but could you explain how to even start approaching this from a RE/malware analysis perspective?
I'm guessing there's no drag-and-drop de-obfuscate tool like there is for some of the common .NET obfuscators.
Do you just rely on behavioral/dynamic methods?