The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Loki botnet controller located at 220.127.116.11 on port 80 (using HTTP POST):
domynuts.ga. 300 IN A 18.104.22.168
$ nslookup 22.214.171.124
Referencing malware binaries (MD5 hash):
c7c2d684884f806bb41bf479d172676c — AV detection: 28 / 67 (41.79)