The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Malware botnet controller located at 5.9.224.199 on port 443:
$ telnet 5.9.224.199 443
Trying 5.9.224.199…
Connected to 5.9.224.199.
Escape character is ‘^]’
Malicious domains observed at this IP address:
hevbzr16.top. 60 IN A 5.9.224.199
hevfgd13.top. 60 IN A 5.9.224.199
hevfzw14.top. 60 IN A 5.9.224.199
hevgdl18.top. 60 IN A 5.9.224.199
hevkoa15.top. 60 IN A 5.9.224.199