The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Malware botnet controller located at 52.235.18.18 on port 30281 TCP:
$ telnet 52.235.18.18 30281
Trying 52.235.18.18…
Connected to 52.235.18.18.
Escape character is ‘^]’
Referencing malware samples:
MD5 c9f67a83623894b769cda3123dd64db7