The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Loki botnet controller located at 104.21.17.236 on port 80 (using HTTP POST):
hXXp://rhinestone.cc/obino/Panel/five/fre.php
$ dig +short rhinestone.cc
104.21.17.236
Referencing malware binaries (MD5 hash):
e49fe965fac546dd81864efdb9863399 — AV detection: 15 / 69 (21.74)