Hi DavidR,

Not only avast! Network Shield to detect, also WOT does not like that IP: http://www.ipvoid.com/scan/85.214.243.87/
see: http://www.mywot.com/en/scorecard/85.214.243.87
Detected Blackhole URL pattern: http://urlquery.net/report.php?id=2467838
Agree with you it mainly could denote a bad website IP block, IP mentioned on malware domain list etc.
This is confirming this: http://62.67.194.183/clean-mx/viruses.php?domain=85.214.243.87&sort=source%20desc
But as the malware there seems “dead”, a FP can be filed…

polonus