Dear All,
Below is the message from our IT security team. seek your feedback.
The sourcetree software is a malicious one and It sends http without http header, some Chinese binary in there (may be they have Chinese developers or Chinese variations of the software?)
Kindly request Altassian to confirm if this is safe (meaning untampered) Please provide the sandbox report and the hash below. I will approve as soon as they confirm that it is safe.
Spawned process "SourceTreeSetup-3.3.9.exe" (Show Process)
Spawned process "Update.exe" with commandline "--install ." (Show Process)
Spawned process "conhost.exe" with commandline "0x4" (Show Process)
Spawned process "SourceTree.exe" with commandline "--squirrel-install 3.3.9" (Show Process)
Spawned process "SourceTree.exe" with commandline "--squirrel-firstrun" (Show Process)
Spawned process "7z.exe" with commandline "x -o%LOCALAPPDATA%\Atlassian\SourceTree\hg_extras -y %LOCALAPPDATA%\Atlassian\SourceTree\mcmw.zip" (Show Process)
Spawned process "conhost.exe" with commandline "0x4" (Show Process)
Spawned process "Windows10UpgraderApp.exe" with commandline "/Install /ClientID Win10Upgrade:VNL:NHV19:{} /SkipEULA /QuietInstall" (Show Process)
Spawned process "HttpHelper.exe" with commandline ""g.bing.com" "/gwx/vanilla?ts=1595356311425&SQM=d72ccd18955546cebe82dd29eb26e920&GWX=(null)&WU=6a1f90ef80e8436381ba21b68ea8f788&WER=(null)&CS=10&OSVersion=10.0.16299&STG=win10vanillastart&ER=Completed&LANG=1