See: https://www.virustotal.com/nl/ip-address/209.202.252.50/information/
This is a Suspicious Cloud destination, Symantec detects Suspicious.Cloud.5, a detection technology designed to detect entirely new malware threats without traditional signatures. This technology is aimed at detecting malicious software that has been intentionally mutated or morphed by attackers.
Avast detects Win32:CIH there.
polonus