it is at R.A.T. Aka Remote Access Trojan I am Pretty sure.
And Avast Had To Close A connection to tcp://185.246.221.154:80 which was a connection to the file the program downloaded at https://RCC-Connection.greasyrooster1.repl.co/SYSTEM_FILE_HOST.vbs