It seems like it first deleted some visual basic scripts in the directory it was executed in, the scripts had this kind of name: YOUR_USERNAME.vbs
Then it downloaded an executable from this website https://coid.xyz/
which has a name like this: icarian_[x86 OR x64].exe
and saved it on you computer as: YOUR_USERNAME.exe
The website had the default Apache landing page, which is unusual for a legit well configured website.
I then runs that executable and places the output in a visual basic script in the format YOUR_USERNAME.vbs
and then executes it.
I do not know how dangerous it is, but I would be concerned myself since this is very shady, the website has a certificate issued from lets encrypt but don't know how much that would help.
check the contents of the visual basic script to see what it does, since this just downloads the stuff to your computer and runs it.