An example here: http://zulu.zscaler.com/submission/show/42f35ef348005a584f84726a16a48ee8-1342967479
There is a whole plethora of these requests mentioned here: http://www.google.nl/url?sa=t&rct=j&q=tool%2Fdtsys.exe%3F%2522%2F%2F%3B&source=web&cd=1&ved=0CFEQFjAA&url=http%3A%2F%2Fwww.malwareblacklist.com%2FsearchClearingHouse.php%3Fsearch%3D218.38.12.110%2Ftool%2Fdtsys.exe%3F&ei=PRAMUJ-iKKrS0QX71tyxCg&usg=AFQjCNE_urjwu7ab9jLXPxUUuMn2LrFAMA
Site blacklisted, malware not identified
Here avast detects: https://www.virustotal.com/file/2c2d943c26c92f0b8368d0cb3b759a84523b19248d421472560c484cf917a889/analysis/
IDS alerts given here: http://urlquery.net/report.php?id=99338
Also found here: https://raw.github.com/technoskald/cifexamples/master/url-snort (alerts are generated mainly heuristically)
Threat identified as drive-by-download for TR/Dldr.Delphi.Gen (most instances closed or dead),
polonus