inside the JS it makes an call to a shit website where then its sends data like database information ip hostnames etc and searches for passwords stored in windows all of em(webbrowsers&managers). then it send back the virus you called not really an virus but just steals your code and send it to these websites:
127.0.0.1 admin-panel.sbs
127.0.0.1 1ls2.org
127.0.0.1 uwumiau.xyz
Its using js to download its hashed so i couldnt find out but i found where it is heading too the information.
Then it infects all the lua with fake information like server and client script wich exist of 3 letters. like xhd.js
If you did use this already just block these in your hosts file
wich should be found here: YOURDRIVE:\Windows\System32\drivers\etc
127.0.0.1 cipher-panel.me
127.0.0.1 ciphercheats.com
127.0.0.1 keyx.club
127.0.0.1 dark-utilities.xyz
127.0.0.1 spectre.sbs
127.0.0.1 ketamin.cc
127.0.0.1 pqzskjptss.shop
127.0.0.1 admin-panel.sbs
127.0.0.1 1ls2.org
127.0.0.1 uwumiau.xyz
What is the virus name ?
Because im using it i just removed the backdoors and its working as charm and incase you get infected just look what the virus does an where it sends data to and block it from hosts.
worst case scenario reformat 😄