Brute force attacks to /wp-login.php and /wp-admin this is the Global Issue for WordPress sites
For WordPress admin protection you need to install plugin for change the standard authorization address to your personal one.
For plugin installation You need to login in WordPress admin of Your site:
Go to part "Add New" there in the search form, specify "wp hide":
In the search results, select the "WPS Hide Login" plugin and click "Install Now":
After Installation go to part "Plugins / Installed Plugins". Click "Activate" under "WPS Hide Login" plugin:
Go to plugin setting after activation:
Go to down page the field "Login URL":
Plugin default folder name "login", but you can rename to convenient option for yourself, for example "myadmin".
After saving the settings, you will see a message:
We recommend storing the address in bookmarks