My suggestions:
If your server has confidential/money related info. take down the server.
If not , wait because even if you bring up new server. How do you know , he won't crack it again?
- Check your /var/log/messages & audit.log & ssh/d.log
I'm impressed that my home server has logged over 650,000 failed logins since 1 July, and a couple of machines I administer in a university over 300,000 each. That's every three-four seconds for the home server.
- Check your /var/log/messages & audit.log & ssh/d.log
- Check lastb & last command outputs
- Take dump of network connections. (netstat)
- find out his 'tty' and spy on him! with something like sysdig or using strace (http://serverfault.com/a/423666)
Most importantly do these after turning off bash_history.So that attacker won't see you are gather information.
I assume you are running Linux server.