Microsoft Edge Add-ons Verified

Synballo

bff49244-9e8d-52ae-a600-03290671e820 | v0.8.0
65/ 100
MEDIUM risk
No change since v0.7.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.

Analysis record

Analysed
3 weeks ago
Version
v0.8.0
Artifact
SHA256 AF3…AF0
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

37 detail rows

YARA Rule Matches

7 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 4
content.jssymbols.jsbackground.js +1 more
-
LOWpostinstall crypto operations 2
_metadata/verified_contents.jsonbackground.js
-
LOWpostinstall file manipulation 5
content.jsoptions.jsabout.md +2 more
-
LOWpostinstall obfuscation 1
content.js
-
LOWpostinstall network communication 6
content.jsoptions.jssymbols.js +3 more
-
LOWpostinstall system command 3
_metadata/verified_contents.jsonsymbols.jsbackground.js
-
LOWpostinstall persistence mechanism 2
symbols.jsbackground.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

17 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

vir2alexport

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

28
Noisy-finding weight
x1.00
Publisher domain
synballo.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

2
Obfuscation
1
Network
17
IoC Indicators

YARA Rules Matched

7 rules(23 hits)
postinstall file download postinstall crypto operations postinstall file manipulation postinstall obfuscation postinstall network communication postinstall system command postinstall persistence mechanism

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The Synballo extension presents findings that are predominantly explainable as known false-positive patterns documented in CVEQ analysis guidelines.

The IoC findings (18 total) consist almost entirely of garbage patterns: XIOC-IP-d:: is an IPv6 hex substring fragment, not a real IP address. XIOC-DOMAIN-date.now, XIOC-DOMAIN-e.target, and XIOC-DOMAIN-uid.review are JavaScript property access chains misidentified as domains. The Microsoft Edge store URL https://edge.microsoft.com/extensionwebstorebase/v1/crx is benign infrastructure. The https://creativecommons.org/licenses/by-nd/4.0/legalcode URL is a standard open-source license reference. The remaining IoCs point to synballo.com, which is the extension's own domain used for donation, rating, and update tracking—expected behavior for a legitimate extension.

The single network finding NET-FETCH-background.js:72 indicates a fetch call in the background script. This is standard for extensions that need to communicate with their own services, and without evidence of suspicious destination domains or data exfiltration patterns, this is benign behavior.

The findings summary reports 15 malware-signature findings, but the evidence bundle does not include the actual signature details. Without knowing what specific signatures triggered, these cannot be evaluated. The 2 obfuscation findings similarly lack detail.

Strongest Counterargument: A skeptic would argue that 15 malware-signature findings from an anonymous developer (vir2alexport) with zero users and an unknown version warrants a malicious verdict. However, the visible findings do not demonstrate any high-confidence threat indicators: no typosquatting (the extension doesn't impersonate a known brand), no browser hijacking (no custom search engines or new tab replacement), no credential theft (no targeting of login domains), and no malware delivery disguise (not a Flash emulator or fake VPN). The malware-signature count alone, without specific signature names or malicious code evidence, cannot override the fact that all visible IoCs are known false positives. The verdict would change if the malware signature details revealed actual malware families like Emotet, TrickBot, or specific credential-stealing signatures.

The extension's description matches its category (symbol picker/emoji keyboard), and the network behavior is consistent with a legitimate utility extension. The evidence quality is moderate because the malware-signature findings lack detail, preventing full assessment of those specific signals.

Key Reasons

  • All visible IoCs are known false-positive patterns
  • No high-confidence threat indicators present
  • Extension domain usage is legitimate self-reference
  • Network activity is standard fetch behavior
  • Malware-signature details not provided for evaluation

False Positive Considerations

  • IPv6 fragment garbage (d::)
  • Property access chains misread as domains (date.now, e.target, uid.review)
  • Extension's own domain (synballo.com)
  • Benign infrastructure domains (edge.microsoft.com, creativecommons.org)

Reviewed 2026-05-03; recommended action: suppress false positive; model confidence 75%.

Edge version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
65
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
0.7.0
Apr 4, 2026
Risk range
65 to 65
Across analyzed versions
Latest analyzed version
0.8.0
Sep 7, 2026
Selected version
medium
Version
v0.8.0
3 weeks ago
Risk score
65
Findings
54
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions