The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Loki botnet controller located at 185.251.91.120 on port 80 (using HTTP POST):
hXXp://hstfurnaces.net/gd4/fre.php
hstfurnaces.net. 600 IN A 185.251.91.120
Referencing malware binaries (MD5 hash):
0d5b6c1f4ae4856fb7e00acd033c7938 — AV detection: 20 / 70 (28.57)
c31729091a6715d479bb9c8cb1a40e57 — AV detection: 23 / 71 (32.39)