The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Malware botnet controller located at 80.249.149.129 on port 443:
$ telnet 80.249.149.129 443
Trying 80.249.149.129…
Connected to 80.249.149.129.
Escape character is ‘^]’
Malicious domains observed at this IP address:
hevbhs27.top. 600 IN A 80.249.149.129
hevdle24.top. 600 IN A 80.249.149.129
heveop28.top. 600 IN A 80.249.149.129
hevjaz25.top. 600 IN A 80.249.149.129
hevyxb23.top. 600 IN A 80.249.149.129