See: https://cymon.io/31.170.165.33 & https://www.threatminer.org/host.php?q=31.170.165.33
and https://www.threatcrowd.org/ip.php?ip=31.170.165.33 & http://liveipmap.com/31.170.165.33
and http://www.openclam.com/?page=31.170.165.33
earlier given at http://lists.clean-mx.com/pipermail/phishwatch/20160325/126272.html
avast detects JS:Downloader-DFL [Trj] from that IP. Missed here? → http://www.ipvoid.com/scan/31.170.165.33/
polonus