The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Malware botnet controller located at 40.117.139.198 on port 7974 TCP:
$ telnet 40.117.139.198 7974
Trying 40.117.139.198…
Connected to 40.117.139.198.
Escape character is ‘^]’
Referencing malware samples:
MD5 4bf99105c5d9bbc157aa9d697caa3b8b