It works, but since activated (we renamed the wp-login.php to wp-protected), we are receiving suspicious process on wp-login.php from our firewall.
Command Line (often faked in exploits):
/opt/cpanel/ea-php56/root/usr/bin/php-cgi /home/username/public_html/wp-login.php
130 notifications, only in the last hour.
Why is that, what can we do, where to look for?
Regards,