The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Malware botnet controller located at 65.21.127.115 on port 18297 TCP:
$ telnet 65.21.127.115 18297
Trying 65.21.127.115…
Connected to 65.21.127.115.
Escape character is ‘^]’
$ nslookup 65.21.127.115
65-21-127-115.serverhub.ru
Referencing malware samples (MD5 hash):
362592241e15293c68d0f24468723bbb — AV detection: 40 / 70 (57.14%)