Hello, sorry for late answer, but it did not help. I have tried "tcpdump -G 60 -W 1 -i eth0 'port 28960' -w output.pcap".
File sile was about 100mb in few seconds, when I opened it, there were so much IP addresses sending packets to port 28960.

All packets were very similar to this: (idk if you need it or something.. If you need something else, send pm or so.)
Click image for larger version. 

Name:	packet.PNG 
Views:	68 
Size:	10.3 KB 
ID:	1360


Is there any other way what can I try? :/