Cisco bridges running a multicast suppression mechanism will always flood multicast frames destined for 01-00-5E-00-00-00 to01-00-5E-00-00-FF.
This looks like an attempt to preserve operation of (inter)network control traffic using the reserved 126.96.36.199/24 address block, and seems reasonably paranoid.
Is this codified as a requirement anywhere? Chapter and verse?
The only references to it that I can find are in Cisco documentation, and in RFC4541, where it appears as a question, but doesn't make clear where the requirement comes from.