The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
OskiStealer botnet controller located at 104.21.96.64 on port 80 (using HTTP POST):
hXXp://golfhomexpresx.ir/7.jpg
$ dig +short golfhomexpresx.ir
104.21.96.64
Referencing malware binaries (MD5 hash):
8fba526b759a51885a2f1a0f26ae040f — AV detection: 17 / 68 (25.00)