The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Smoke Loader botnet controller located at 220.127.116.11 on port 80 (using HTTP POST):
ejeana.co.ug. 600 IN A 18.104.22.168
Referencing malware binaries (MD5 hash):
623ef5cd7c56c96132336938466c9c16 — AV detection: 13 / 63 (20.63)