The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Malware botnet controller located at 220.127.116.11 on port 80 (using HTTP POST):
$ nslookup 18.104.22.168
Referencing malware binaries (MD5 hash):
35718909f91d0229ab56cb060cb2284f — AV detection: 6 / 64 (9.38)