While monitoring my office's network, I have seen a huge amount of traffic coming from devices whose MAC address manufacturer part (the three most significant octets) is 00:FF:01
I can't see the client part, but this prefix is showing ~50% more traffic than any other device from any other manufacturer.
I haven't been able to find who's the manufacturer of such a device, or whether is some kind of virtual device (all the queries out there return a No manufacturer found for that prefix)
I'm not even sure if ServerFault is the right place to ask this, but I'm running out of options. Does anyone knows what type of device is that? Are they virtual devices?
Thank you in advance.
EDIT 1:
Running WireShark I was able to find the whole MAC of one of these things: 00:FF:01:FF:02:FF
(it really looks weird for a MAC address). For the last... 30 mins or so, only that particular MAC address seems to be sending traffic. I don't know for sure if all the hits I saw before (the ones where I could only see the manufacturer part) were coming from the same 00:FF:01:FF:02:FF
, or if there's a possibility there were other devices with the same manufacturer 00:FF:01
but they're not transmitting now.