Probably just testing for some vulnerability. If you’re current on patches, you can just disregard as background noice. If it really happens a lot, setting up something like Fail2ban would be useful.
Edit: A quick google search suggests it looks like a Windows Remote Desktop packet header. So something scanning the internet for machines with open RDP




Other users cannot. Your instance admin can obviously see it if they want. Then, it depends on the settings of your instance if all media downloads from other instances are proxied through your instance (hiding your IP from other instance admins) or not. I’m not sure if it’s enabled by default or not.