Ransomware Series: CredPhish Fake Windows Update Credential Phishing via first.p
Detects the execution of PowerShell scripts 'first.ps1' and 'main1.ps1', which are components of a known credential phishing toolset. This tool displays a fake Windows Update dialog to trick users into providing their credentials, which are then exfiltrated via SMB, DNS, or HTTP.
Sigma

