The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Malware botnet controller located at 52.231.103.159 on port 5901 TCP:
$ telnet 52.231.103.159 5901
Trying 52.231.103.159…
Connected to 52.231.103.159.
Escape character is ‘^]’
Referencing malware samples:
MD5 a7705ae531841779f8054c912b6f7ad0