Is it the external link to htxp://ad.z5x.net, one of the adservers that Trojan.Obvod etc. tries to connect to a.o. that is being flagged?
Well there is quite some malware spread from that IP via various domains: JS-includer:BI & Worm.VBS.awl * unknown_html - all up and alive, see:
http://support.clean-mx.de/clean-mx/viruses.php?review=213.131.252.251&sort=id%20desc
Worm.VBS.awl not being detected here: https://www.virustotal.com/nl/file/bedd55043fd4901eaac1e4624b427db26cbac8659a9490943fd51f2610323ec2/analysis/
polonus