The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Malware botnet controller located at 188.8.131.52 on port 21 TCP (FTP user name: firstname.lastname@example.org):
$ telnet 184.108.40.206 21
Connected to 220.127.116.11.
Escape character is ‘^]’
$ nslookup 18.104.22.168
$ dig +short ftp.dveshop.ro
Referencing malware samples (MD5 hash):
2e65e1e1cbc00f87cc1756e9c37dd93a — AV detection: 22 / 73 (30.14%)