The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Malware botnet controller located at 52.231.26.149 on port 6903 TCP:
$ telnet 52.231.26.149 6903
Trying 52.231.26.149…
Connected to 52.231.26.149.
Escape character is ‘^]’
Referencing malware samples:
MD5 3035bdee68c6e1bb1eafa8bcf6509971