Wiping disks before a ddos is pretty weird. Usually, a ddos is just someone being a dick or someone trying to extort you. You are either dealing with two attackers or someone who's motivation is to put you out of business. Two attackers is unlikely. That just leaves putting you out of business. Suspects would be competitors, governments and NGOs. It will take serious infrastructure and expertise to deal with a threat like that. Hopefully I'm wrong, and it's just some asshole kid who will get bored with you in a few days.

Reply to this note

Please Login to reply.

Discussion

Yea I think you might be right, unfortunately there is no logs on the VM anymore its all zeros, not even a partition table

You should have offsite logging that attacker cannot wipe in case of compromise of this machine