Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Black Basta

173
Global rank
170 infographic chevron month
Month rank
157
Week rank
0
IOCs

Black Basta is a ransomware-as-a-service operated by Storm-1811. It emerged in 2022 and uses double extortion tactics, encrypting data and stealing it for ransom. The malware often gains access through spear-phishing and uses tools like QakBot and Cobalt Strike. It's known for exploiting system vulnerabilities and using advanced obfuscation techniques.

Ransomware
Type
Unknown
Origin
1 February, 2022
First seen
9 July, 2026
Last seen

How to analyze Black Basta with ANY.RUN

Type
Unknown
Origin
1 February, 2022
First seen
9 July, 2026
Last seen

IOCs

IP addresses
34.107.243.93
23.52.181.141
172.211.123.248
20.74.47.205
20.31.169.57
74.178.240.51
23.11.40.157
48.192.1.64
88.221.169.124
151.101.129.91
20.190.160.67
48.209.138.189
20.190.159.64
151.101.1.91
2.23.246.101
88.221.169.152
34.160.144.191
23.216.77.28
20.165.94.63
204.79.197.203
Hashes
81b2bd4ea98c8db66554fbc8d7637a1a69a130f331feb732b75caab4c4868fd5
704d28223a4320a853df4a19d48c7015cf79d56a5317cc3475b6305fa43dcc05
7bfbc8202b8cdbdcc597a0e789240f0dc0b0e94fa6597e576eaf436bc6223e18
84e58efe7002b3979bd085be539f0b77c4e4088cf36871d2064b955cf8e49c41
0c6c1246ff1fcbf1ac16dfe53be24ee7891de62a4bfedeeb632faa7caee262a8
eacdcd9e8741abb98b24148a7ca985b701a1892dd0420caeb9c641c5df80f16c
82d41331f06732620466adfb237bd23a7b16ca26d35609795fa3a92d4f22561d
a8851a88336b4fa306147f7f8cae11faaf679d22d0c94f7200d2769d1f3596ad
ef90e0f733fbd90d559cbf14c5c7b895d45e5c1a1d03d2ed8598b0abfb30f655
d953f5e31a5d7c8516262c503c04cf2f1a6a7ca368b55b732ba5c1ad78b0322a
b32a837702b91f3d6c3a6a50da2e31f1cbe6384e991aefd08eb595a05dd27761
7cea48e7add3340b36f47ba4ea2ded8d6cb0423ffc2a64b44d7e86e0507d6b70
792955295ae9c382986222c6731c5870bd0e921e7f7e34cc4615f5cd67f225da
00ad9799527c3fd21f3a85012565eae817490f3e0d417413bf9567bb5909f6a2
fdd1df762ccf2c036aef6e14b2f13e2e00e2bbd3f7485ba79ba25035352d3b5c
8b25d2f6f3cfc412ae3a4f0f6680b3a240bb470c7b0bc95afd237c3952da7ada
6d37b708cd14b7b282ed6a7ee2c06411fc6321a2239a937f001a3d9fe642db54
e3fdd98dda87abc0d29a25b4de25db2a66f18582105a9b8d168c46141396a4ed
21091d52a53741d7747175ba2f9e2576ef10b0977592b4993583ba75b128ebfa
8abc7c359f671ce7656754962aba3097fb877fd0d4d088b19e94c5878dc43ee2
Domains
settings-win.data.microsoft.com
nexusrules.officeapps.live.com
oneocsp.microsoft.com
spocs.getpocket.com
slscr.update.microsoft.com
normandy.tombstone.experimenter.prod.webservices.mozgcp.net
detectportal.firefox.com
firefox.settings.services.mozilla.com
www.bing.com
contile.services.mozilla.com
go.microsoft.com
content-signature-2.cdn.mozilla.net
accounts.firefox.com
google.com
example.org
mozilla.map.fastly.net
arc.msn.com
firefox-settings-attachments.cdn.mozilla.net
www.microsoft.com
normandy.cdn.mozilla.net
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://www.bing.com/rp/anzunpnvy0ol0xwxs0rljxjjluo.br.js
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaagb6jmmcovb6saaaaaaay%3d
https://www.bing.com/threshold/xls.aspx
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9
https://www.bing.com/manifest/threshold.appcache
https://www.bing.com/as/api/windowscortanapane/v2/init
https://www.bing.com/web/xlsc.aspx?t=5&dl=1&f=9&wsbc=1
https://www.bing.com/rb/1c/cc,nc/8qgg5w3ncsqflirnejktkex2-pa.css?bu=ehn6cyakexmqcnmwcpgkexl5owqlcnl5&or=w
https://www.bing.com/rb/1c/cc,nc/dkse3syhvijzh9mpm4nc3lq7l5i.css?bu=d5cjnamecxmpcb4jxal51al5eeojexmlcg&or=w
https://www.bing.com/rb/2g/jnc,nj/mxejyjngl4wpe6lwn5khkr4_-94.js?bu=avqclau&or=w
https://www.bing.com/rp/1upz2giusmqtlexh3fc43gaociu.br.js
https://www.bing.com/rp/3ewwwwrfxnbg0zoa-nopleviyyk.br.js
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://www.bing.com/rp/47gtxbjjuwc12hjrmz9doxytzra.br.js
https://www.bing.com/rp/54gnhw5any81inhrc24jhrw6sho.br.css
https://www.bing.com/rp/6uc4gkck_zhco-ammrthwsrabf8.br.js
https://www.bing.com/rp/9t-mdpdto2bxcai6g8qbbfnltb0.br.css
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2536
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7351
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10494
comments 0

What is Black Basta ransomware?

Black Basta is a malware that falls under the category of ransomware-as-a-service (RaaS). This software is operated by the cybercrime group known as Storm-1811. First detected in 2022, Black Basta has gained attention for its tactics.

The strategy of Black Basta involves double extortion. Unlike traditional ransomware that only encrypts the victim's data, Black Basta also steals it. This dual threat strategy involves demanding a ransom for both the decryption of the data and the non-disclosure of the stolen information. The ransom demands can reach up to $2 million.

The operators of Black Basta set up a website where they publish information about their victims. This site also serves as a platform for leaking data of those who refuse to pay the ransom.

One of the first victims of Black Basta was the American Dental Association, an organization with over 100,000 members. The attack led to a partial shutdown of their infrastructure.

In their attacks, the operators of Black Basta have used QakBot as a means of initially breaching target systems. This tactic allows them to gain a foothold in the system, subsequently deploying the ransomware to encrypt and steal data. The use of QakBot underscores the complexity of the Black Basta attacks.

Black Basta ransomware execution process

To prevent Black Basta infection, it is important to proactively upload all suspicious files and links to the ANY.RUN sandbox. Here is an example of a malicious Black Basta sample, exposed by the service. Let’s break down the entire infection chain step by step:

Step 1: Black Basta can gain initial access through compromised credentials or be delivered to the system by other malware like Qbot.

Step 2: Black Basta then gathers information about the compromised system.

Step 3: The malware operators use tools like PsExec, Windows Management Instrumentation (WMI), and RDP to move across the network and infect other systems.

Step 4: Before deploying the ransomware, sensitive data is exfiltrated using tools like Cobeacon.

BlackBasta wallpaper in ANY.RUN BlackBasta wallpaper in ANY.RUN sandbox

Step 5: As mentioned, Black Basta samples can employ different versions of encryption. One of them is a hybrid encryption scheme combining ChaCha20 for file encryption with RSA-4096 for encrypting the encryption key.
BlackBasta ransom note in ANY.RUN BlackBasta ransom note in ANY.RUN sandbox

Step 6: A note is displayed on the victim's screen, and a text file with details on how to pay the ransom for decryption.

Step 7: To prevent recovery, Black Basta deletes shadow copies using commands like vssadmin.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Black Basta malware technical details

Black Basta employs a range of technical tactics to infiltrate and manipulate target systems. One common method involves hijacking the legitimate system process 'Fax'. The malware deletes the process first, then creates a new registry path to gain elevated privileges within the system.

Once it has infiltrated the system, Black Basta deletes Windows shadow copies via 'vssadmin'. It then changes the wallpaper to announce that the user's computer has been infected by the Black Basta group. Following this, the system is restarted in safe mode.

To bypass system defenses, the malware uses PowerShell to disable active antivirus software. Earlier versions of Black Basta used the ChaCha20 encryption algorithm, later switching to XChaCha20. The malware adds the '.basta' extension to the affected files, indicating their encryption.

Instructions for the victim's further actions are provided in text documents. These documents contain a Tor address and a unique ID for the victim to log in on the website.

As mentioned, many Black Basta attacks have been known to start with QakBot. This is done to establish an initial foothold on the system to then deliver the ransomware. Such attacks begin with the victim unsuspectingly downloading an Excel document with macros. The attack then leads to the malware download and installation process.

The operators of Black Basta also employ Cobalt Strike as a means of scanning the system. This tool allows them to gather information about the target system, identify vulnerabilities, and tailor their attacks accordingly.

The newer versions of the malware, emerging in 2023, utilize advanced obfuscation techniques to evade detection. The malware can also modify the registry to run automatically upon system startup.

Black Basta can also collect credentials stored on the system, further compromising system security.

The latest variants of Black Basta exploit the CVE-2024-1709 vulnerability. The malware is capable of performing lateral movement via tools like PsExec and Cobalt Strike, spreading the infection across the network.

In addition to these tactics, the attackers have started using Quick Assist, a legitimate program for remote connection, as part of their social engineering attacks. This tool allows them to gain remote access to the victim's system, further facilitating the malware's activities.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Black Basta malware distribution methods

Black Basta operators often get into systems by using compromised login information. To do this, they work with Initial Access Brokers (IABs), selling access to already hacked networks. In return, they receive a share of the profits.

Many Black Basta attacks also begin with spear-phishing campaigns. These campaigns involve sending targeted emails to victims, often disguised as legitimate correspondence. The emails typically contain malicious attachments or links, which, when clicked or downloaded, initiate the malware infection process.

The latest attacks featuring Black Basta also include vishing, or voice phishing. This involves the impersonation of tech support or help desk personnel. The attackers use Quick Assist, a legitimate remote access tool, to trick users into entering a code provided by the attackers. This code allows the attackers to establish remote control over the victim's computer, subsequently downloading malicious files onto the host system.

Conclusion

Black Basta's double extortion, concealment, and abuse of system vulnerabilities make it a significant threat for organizations worldwide. To keep safe from ransomware, it's crucial to adopt suitable cybersecurity practices, including employing a sandbox for analyzing malware.

ANY.RUN's interactive sandbox offers various tools that make malware analysis simpler and faster. It can:

  • Discover threats in files and URLs in less than 40 seconds.
  • Allow direct interaction with the samples and system, similar to a standard computer.
  • Provide Windows and Linux virtual machines to fit your specific needs.
  • Generate in-depth reports describing the threats found.
  • Reveal all malicious activities related to the network, registry, files, and processes.

Create your FREE ANY.RUN account today!

HAVE A LOOK AT

RedLine screenshot
RedLine
redline stealer redline stealer malware
RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.
Read More
Virlock screenshot
Virlock
virlock
Virlock is a unique ransomware strain that combines encryption capabilities with file infection techniques. First observed in 2014, it stands out due to its polymorphic nature and ability to embed its code into compromised files, ensuring continued propagation. Once it infects a system, it encrypts files and locks the screen, demanding a ransom for file recovery and system access.
Read More
OnyxC2 screenshot
OnyxC2
onyxc2
OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.
Read More
PhantomEnigma screenshot
PhantomEnigma
phantomenigma
PhantomEnigma (also known as Operation Phantom Enigma) is a sophisticated crimeware operation primarily targeting banking organizations and the public sector in Brazil. The campaign is characterized by its strategic abuse of compromised legitimate infrastructure, specifically Brazilian government (.gov.br) portals and municipal websites, to host and distribute malicious payloads.
Read More
Moonrise screenshot
Moonrise
moonrise
Moonrise RAT is a newly discovered Go-based remote access trojan with zero detections at launch, featuring credential theft, keylogging, webcam access, clipboard hijacking, and UAC bypass.
Read More
FatalRAT screenshot
FatalRAT
fatalrat
FatalRAT is a malware that gives hackers remote access and control of the system and lets them steal sensitive information like login credentials and financial data. FatalRAT has been associated with cyber espionage campaigns, particularly targeting organizations in the Asia-Pacific (APAC) region.
Read More