Cert Graveyard Report

Certificate Signer: Osh Spetsstroy LLC
Certificate Serial: 3D 7B 3B 37 5F E1 43 46 65 CB F4 3E F2 11 91 68

All Cert Graveyard entries are considered malware. Other files by the same certificate serial number should be considered suspect.
Trojan:Win32/DefenderPlug.Keylogger
5f80100560c0422cfd71a5138d65f1124287d2bf9f941c33add56ee9626b071b
3D 7B 3B 37 5F E1 43 46 65 CB F4 3E F2 11 91 68
Osh Spetsstroy LLC
SSL.com EV Code Signing Intermediate CA RSA R3
2026-07-08 15:24:27
2027-07-08 15:24:27
2026-08-07 19:14:49 UTC
Signed keylogger/infostealer masquerading as a Webroot security product ("DefenderPlug", ProductName "BrowseSecure") while its embedded manifest simultaneously claims to be Microsoft.Windows.RuntimeBroker. Signed with a valid SSL.com EV Code Signing certificate issued to "Osh Spetsstroy LLC" (KG), serial 3D7B3B375FE1434665CBF43EF2119168, signed 2026-08-06 11:39:56 UTC, NOT revoked as of 2026-08-07. Imports GetAsyncKeyState, GetForegroundWindow, SetTimer and GetDlgItemTextA (keystroke capture incl. reading foreign window controls). Writes to %APPDATA%\DefenderPlug, exfiltrated to https://wcz2ps4v-8443.use.devtunnels.ms/. Part of a fake Windows-update package that also deploys a persistent