This technical report investigates the Black Basta ransomware, which emerged in April 2022 and affected numerous organizations across North America, Europe, and Asia. The report outlines the ransomware's operation as a ransomware-as-a-service (RaaS) model that utilizes double extortion tactics, including data encryption and exfiltration. The document details the methods used to identify indicators of compromise (IoCs) associated with Black Basta, including WHOIS data analysis and IP geolocation lookups. It presents findings on domains and IP addresses linked to the ransomware, revealing connections to malware distribution campaigns disguised as courier services and OneNote documents. The report emphasizes the urgency of detecting Black Basta IoCs, as they pose significant risks to cybersecurity by potentially shutting down endpoint detection and response solutions. The investigation led to the discovery of over 1,200 artifacts, many of which have been involved in malicious activities, highlighting the need for ongoing vigilance and research in this area.