The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Loki botnet controller located at 35.238.66.156 on port 80 (using HTTP POST):
hXXp://frinqy.gq/apps/fre.php
$ dig +short frinqy.gq
35.238.66.156
$ nslookup 35.238.66.156
156.66.238.35.bc.googleusercontent.com
Other malicious domain names hosted on this IP address:
vs5p2ck.ga 35.238.66.156
frinqy.gq 35.238.66.156
akiwinds.duckdns.org 35.238.66.156