Decrypting Qakbot strings: a full static analysis take

Sample:
21286ed0b3e56f49c287617ee5bf4ef687c627e342d72297008e3fce73a5ae20.lnk (Bazaar, VT)
Infection chain:
backdoored MSI installer (downloader) -> .NET loader -> Qakbot
Tools used:
Malcat
Difficulty:
Easy

MSI installer