A UDID is the result of a SHA-1 calculation: there is no such thing as a 40-character hexadecimal string which is "isn't a valid UDID" by syntax, so this is interesting to me: if the author ever sees this, did you get an error saying that from Apple (in which case we know they have a massive database of every device in existence)?
(Note that UDIDs beginning with 32-bits of F are returned by the APIs that provide app-specific advertising identifiers on the device, so if you saw one of those and decided it was "invalid", that was returned because they used a tool which tried to return a UDID but was using the older public APIs to do that from a sandboxed application.)
(edit: Oh, I just noticed there are comments on the website. I'm stupid, and will copy this there.)