Just because the "attacker" deleted the server logs from a machine he uses as a zombie doesn't mean crap. If you spent the time to build something you aren't going to risk it being torn down willy-nilly... You want it to stay.... so you delete logs so you can use the resource again.....

As far as this being a spoofed attack..... NOT.... He deleted multiple logs with no feedback and only missed the "hidden" one.... Nope.... He had feedback.... The "attacking" machine is compromised..... If it isn't..... You'll never catch the guy..... He is Uber L33t but he never types that way.....

The computer owner is innocent.... He's hacked and he doesn't know it..... But he's innocent.