The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Malware botnet controller located at 40.121.108.109 on port 1996 TCP:
$ telnet 40.121.108.109 1996
Trying 40.121.108.109…
Connected to 40.121.108.109.
Escape character is ‘^]’
Referencing malware samples:
MD5 4b66a4bb643b6ebe7ebefb7c82194c4a
MD5 d2aa6ce87b5a04efe5f7f1781c9532a8