The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Malware botnet controller located at 194.87.185.5 on port 443:
$ telnet 194.87.185.5 443
Trying 194.87.185.5…
Connected to 194.87.185.5.
Escape character is ‘^]’
Malicious domains observed on this IP address:
accountreview-binance.com. 600 IN A 194.87.185.5
ch-compliance-binance.com. 600 IN A 194.87.185.5
ch-accounts-binance.com. 600 IN A 194.87.185.5
ch-compliance-binance.com. 600 IN A 194.87.185.5
ch-investigation-binance.com. 600 IN A 194.87.185.5
dnb-mobilbankno.com. 600 IN A 194.87.185.5
es-blockchain.com. 600 IN A 194.87.185.5
espana-blockchain.com. 600 IN A 194.87.185.5
m-sparebank.info. 600 IN A 194.87.185.5
mmc-ventures.com. 600 IN A 194.87.185.5
nordea-norge.info. 600 IN A 194.87.185.5
nordeafi-peruutus.com. 600 IN A 194.87.185.5
opfi-peruutus.com. 600 IN A 194.87.185.5
ph-accounts-binance.com. 600 IN A 194.87.185.5
tesla-santander.com. 600 IN A 194.87.185.5