The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Loki botnet controller located at 104.21.23.231 on port 80 (using HTTP POST):
hXXp://250b48d798957fbf33b77ae8a74a45ca.cf/Ausin4/fre.php
$ dig +short 250b48d798957fbf33b77ae8a74a45ca.cf
104.21.23.231
Referencing malware binaries (MD5 hash):
718d54f60e56cf100e9ebd53a93b8f5d — AV detection: 19 / 69 (27.54)
Other malicious domain names hosted on this IP address:
api.mdsyzz.info 104.21.23.231
250b48d798957fbf33b77ae8a74a45ca.cf 104.21.23.231