No dstip in http.log when action=blocked for Country and Category block but dstip appears the block is because of virus detection.
Country block (DE):
2014:04:29-07:54:14 test httpproxy[5167]: id="0067" severity="info" sys="SecureWeb" sub="http" name="web request blocked, connection to forbidden country" action="block" method="CONNECT" srcip="192.168.200.200" dstip="" user="" statuscode="403" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="3138" request="0xba6c440" url="https://www.astaro.org" exceptions="" error="" authtime="0" dnstime="0" cattime="0" avscantime="0" fullreqtime="30744" device="0" auth="0" country="Germany"
Category block (General News):
2014:04:29-08:07:24 test httpproxy[5167]: id="0060" severity="info" sys="SecureWeb" sub="http" name="web request blocked, forbidden category detected" action="block" method="CONNECT" srcip="192.168.200.200" dstip="" user="" statuscode="403" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="3163" request="0xbd10220" url="https://www.nbcnews.com" exceptions="" error="" authtime="0" dnstime="0" cattime="716136" avscantime="0" fullreqtime="752483" device="0" auth="0" country="Brazil" reason="category" category="134" reputation="neutral" categoryname="General News"
Category block (Malicious Download):
2014:04:29-08:09:54 test httpproxy[5167]: id="0060" severity="info" sys="SecureWeb" sub="http" name="web request blocked, forbidden category detected" action="block" method="GET" srcip="192.168.200.200" dstip="" user="" statuscode="403" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="3204" request="0xbc77ba0" url="http://www.f-secure.com/virus-info/eicar.zip" exceptions="" error="" authtime="0" dnstime="0" cattime="231614" avscantime="0" fullreqtime="575316" device="0" auth="0" country="United States" reason="category" category="204" reputation="malicious" categoryname="Malicious Downloads"
Virus detection logs dstip (dropped Malicious categories from config):
2014:04:29-08:15:49 test httpproxy[1151]: id="0056" severity="info" sys="SecureWeb" sub="http" name="web request blocked, virus detected" action="block" method="GET" srcip="192.168.200.200" dstip="188.40.238.250" user="" statuscode="403" cached="0" profile="REF_DefaultHTTPProfile (Default Web Filter Profile)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2669" request="0x1c7a8440" url="http://www.eicar.org/download/eicar_com.zip" exceptions="" error="" authtime="0" dnstime="118" cattime="0" avscantime="757" fullreqtime="1713629" device="0" auth="0" content-type="application/octet-stream" engine="Avira" virus="Eicar-Test-Signature"