1 | initial version |
pcap showing broadcast about every 12 seconds
https://drive.google.com/file/d/1TeAtAp1lQNMi3oU27vWU6pY61FiCtQZw/view
The data is anonymized. Mainly contains 0's.
sysinternals Process Monitor running on source machine
Options -> Show Resolved Network Addresses
Filter: Path Contains 889
Show Network Activity
sysinternals TCPView - it happens to be listening on the same port
Since it's listening you could also find it with netstat -anbp UDP