The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Loki botnet controller located at 184.108.40.206 on port 80 (using HTTP POST):
checkvim.com. 600 IN A 220.127.116.11
Referencing malware binaries (MD5 hash):
641e4b752fd10161725fb21afd0fa938 — AV detection: 12 / 68 (17.65)
6ca6261ec795a89a0c7affe7908082ff — AV detection: 10 / 68 (14.71)