The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Malware botnet controller located at 185.251.90.227 port 443:
$ telnet 185.251.90.227 443
Trying 185.251.90.227…
Connected to 185.251.90.227.
Escape character is ‘^]’.
Malicious domains observed on this IP address:
guardns.biz. 600 IN A 185.251.90.227
localdns.biz. 600 IN A 185.251.90.227