The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Loki botnet controller located at 104.21.57.109 on port 80 (using HTTP POST):
hXXp://frostandkeelinginc.cf/Ausin1/fre.php
$ dig +short frostandkeelinginc.cf
104.21.57.109
Referencing malware binaries (MD5 hash):
051af1d7d4c27b66225897eaac5bd11f — AV detection: 35 / 69 (50.72)