The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Malware botnet controller located at 20.194.23.12 on port 5901 TCP:
$ telnet 20.194.23.12 5901
Trying 20.194.23.12…
Connected to 20.194.23.12.
Escape character is ‘^]’
Referencing malware samples:
MD5 913e9853d815202a3d88862bb1fec90f