On my captured network traffic i observe a flow having a source udp port of 26221 and have different destination udp ports. Some of these destination ports were standards IANA ports. The average packet size of these flows were 145 bytes and there were 364 packets within a minute of captured traffic.The destination addresses contains 2 unused ip addresses in IANA table, after 7 minutes the PC resume sending on the same port but the packets size was different.
Any body know if it is a normal traffic or not? any further check I may use to determine if this is benign or not? I goggled for port 26221 but i didn't find something about it.