The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Malware botnet controller at 176.9.148.153 on port 443.
$ telnet 176.9.148.153 443
Trying 176.9.148.153…
Connected to 176.9.148.153.
Escape character is ‘^]’
Malicious domains observed at this IP address:
amazinginvezt.org. 60 IN A 176.9.148.153
btc-es.net. 60 IN A 176.9.148.153
btc-es.org. 60 IN A 176.9.148.153
btcbill.net. 60 IN A 176.9.148.153
btcbill.org. 60 IN A 176.9.148.153
crypt-invezt.net. 60 IN A 176.9.148.153
gas-invest.com. 60 IN A 176.9.148.153
gazivest.net. 60 IN A 176.9.148.153
investgas.net. 60 IN A 176.9.148.153
nbk-invest.org. 60 IN A 176.9.148.153
obszhee-delo.org. 60 IN A 176.9.148.153
plan2-live.org. 60 IN A 176.9.148.153
pr-invest.org. 60 IN A 176.9.148.153
success-finance.org. 60 IN A 176.9.148.153
ultra-signals.com. 60 IN A 176.9.148.153