My KVM VPS is getting flooded with these (thousands every second). I modified the source IP but it's originating from within the provider's network.
0:42:18.750528 IP 123.234.0.22.50138 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.753594 IP 123.234.0.22.50138 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.753650 IP 123.234.1.196.45654 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.756515 IP 123.234.0.22.50139 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.756606 IP 123.234.1.196.45654 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.758707 IP 123.234.0.22.50139 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.760652 IP 123.234.1.196.45654 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.769613 IP 123.234.0.22.50140 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.769926 IP 123.234.0.22.50140 > 255.255.255.255.138: NBT UDP PACKET(138)
0:42:18.769959 IP 123.234.1.196.54411 > 255.255.255.255.138: NBT UDP PACKET(138)
Deeper inspection shows some type of SMBtrans request for a resource called Name=\MAILSLOT\BROWSE
Does anyone know what this is?