The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Loki botnet controller located at 104.21.37.76 on port 80 (using HTTP POST):
hXXp://mainlandtoisland.ml/BN2/fre.php
$ dig +short mainlandtoisland.ml
104.21.37.76
Referencing malware binaries (MD5 hash):
c02cb63889491bf66eb4c4393c484e05 — AV detection: 24 / 68 (35.29)
Other malicious domain names hosted on this IP address:
www.instantsdiscount.gq 104.21.37.76
mainlandtoisland.ml 104.21.37.76