Spoofing 127.0.0.1 localhost.localdomain

Hi, I have an entry under “Top Offending IP Addresses” showing “127.0.0.1 localhost.localdomain.” It is probing the usual URLs like “/settings_production.py” and “/wp-config.php.backup” then gets locked out. I realize that spoofing is going on but can WP Cerber detect this? Is 127.0.0.1 really locked out? Or is the IP of this bad actor locked out? How can I see the IP of the actor behind this spoofing? Thanks in advance and great product BTW.