Microsoft.IdentityModel.Clients.ActiveDirectory.dl file report

MD5 9f99d2f73d03f743af46952bbf914a2c
Latest seen 2025-07-03 23:01:12 (10 months ago)
First seen 2019-03-14 11:36:41 (7 years ago)
Size 186 KB

This report summarizes the file identity, detection status, publisher metadata, observed locations, and technical indicators for Microsoft.IdentityModel.Clients.ActiveDirectory.dl. The latest available status is Clean.

Microsoft.IdentityModel.Clients.ActiveDirectory.dl is a Windows file recorded in the ThreatInfo database. It is associated with Active Directory Authentication Library. The reported company name is Microsoft Corporation. The current detection status is Clean, based on the latest analysis from 2025-07-03 23:01:12 (10 months ago).

This record is currently marked as clean, but file reputation can depend on the exact path, hash, and source. Compare the MD5 and publisher data below with the file on your system.

Product Name: Active Directory Authentication Library
Company Name: Microsoft Corporation
MD5: 9f99d2f73d03f743af46952bbf914a2c
Size: 186 KB
First Published: 2019-03-14 11:36:41 (7 years ago)
Latest Published: 2025-07-03 23:01:12 (10 months ago)
Status: Clean (on last analysis)
Analysis Date: 2025-07-03 23:01:12 (10 months ago)
Signed By: Microsoft Corporation
Status: Trusted Publisher

ThreatInfo marks this publisher as trusted for this record, but the file hash and source should still match the expected software distribution.

%localappdata%
%localappdata%
%localappdata%
%localappdata%
%localappdata%
%localappdata%
%localappdata%
%localappdata%
%localappdata%
%localappdata%

ThreatInfo has observed Microsoft.IdentityModel.Clients.ActiveDirectory.dl in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

9.2%
8.6%
5.7%
5.2%
5.2%
5.2%
4.6%
4.0%
4.0%
3.4%
3.4%
2.9%
2.9%
2.3%
2.3%
2.3%
1.7%
1.7%
1.7%
1.7%
1.7%
1.7%
1.7%
1.1%
1.1%
1.1%
1.1%
1.1%
1.1%
1.1%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%

The strongest geographic signal for this file is Brazil with 9.2% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 76.8%
Windows 7 21.5%
Windows 8.1 1.1%
Windows Embedded 8.1 0.6%

The most common operating system signal for Microsoft.IdentityModel.Clients.ActiveDirectory.dl is Windows 10 with 76.8% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

Microsoft.IdentityModel.Clients.ActiveDirectory.dl is identified as pe for 32 systems. The subsystem is Windows CUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows CUI
PE Type: pe
OS Bitness: 32
Image Base: 0x10000000
Entry Address: 0x0002e39e

.NET Info:

MVID: 37f59d8c-fff0-472c-8016-2c324eff43de
Typelib ID: ff47962a-d498-4c63-b7e9-4db3653ad7da

PE Sections:

Name Size of data MD5
.text 181248 b55c118c2e494d62a73b4dd0992c21dd
.rsrc 1536 06251bbfa66a1f797035fccf86245deb
.reloc 512 43172c4abec4ae3f569c965c4ccf6024

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: