Phil Stokes ⫍🐠⫎
banner
philofishal.bsky.social
Phil Stokes ⫍🐠⫎
@philofishal.bsky.social
macOS security researcher espousing no one's opinions but my own. Dogged follower of #lufc, at least until the world stops going round (IYKYK).
philastokes.com
You know how ppl say you can't decompile run-only #AppleScript ... 😜 #macOS #security
November 7, 2025 at 6:15 PM
🙌 Updated the XProtect-Malware-Families repo to the latest version of XProtect.
💁‍♂️ The repo maps #Apple #malware names to more common names used by security vendors.
#YARA style tags so now you can search for classes of malware like 'infostealer', 'trojan'. #security
github.com/SentineLabs/...
November 4, 2025 at 5:57 PM
OK, I’m in. 🤣 #lufc
September 30, 2025 at 8:18 PM
#Apple's update for #XProtect v5316 includes new rules for #Amos #infostealer. BUT ⚠ XProtect_MACOS_SOMA_SEENC is only detecting bytes in the x86 slice. Thin that binary and you can run the arm slice without detection. #security #macOS
Sample md5: 7f394bdf8f94b7ba9bc6031b5477f556
September 26, 2025 at 3:43 PM
Oh Amy…
September 20, 2025 at 3:19 PM
Does not make for pretty reading. Hope we had a great Int’l break on the training ground and see something different today. #lufc
September 13, 2025 at 10:42 AM
Why would he be sacked? Leeds sit 12th in the table after three games. Above Manchester City, Newcastle, Fulham and Villa.
September 9, 2025 at 8:50 AM
September 2, 2025 at 7:56 AM
W1 D1 L1.
Enjoy your International break! #lufc
August 31, 2025 at 8:33 PM
What’s everyone worried about? We’re playing a team 2pts and three places below us. Should be a stroll… 😉🫣 #lufc 🤍💙💛
August 30, 2025 at 9:38 AM
Cheer up! Leeds 12th or 13th after game week 2. #lufc
🦾 🤍💙💛
August 24, 2025 at 5:28 PM
August 23, 2025 at 3:23 PM
www.theguardian.com/football/pic...
#lufc 🤍💙💛 🤣😂🤣
August 12, 2025 at 12:42 PM
57 more days… 😱😭 #lufc
June 22, 2025 at 5:25 PM
And we're straight onto XProtect v5292! New rule for ToyDrop (aka Adload) and a couple of mods to a few other rules, mostly #adware but also SOMA.G aka Amos Atomic. #macOS #security
April 3, 2025 at 4:28 PM
Nothing much interesting in #XProtect update v5291, just a modification to a recent #Pirrit #adware rule. #macOS
April 2, 2025 at 1:31 PM
Power up your #radare2 pifc command with a $pifc alias that sorts and counts the calls in a function. #macOS #reverseengineering #r2
April 1, 2025 at 1:02 PM
Up next: second-from-bottom Luton, who have just won and now decided they want to be one of the Champo’s in-form teams - fifth in the league to our miserable 12th. 🙀 #lufc
March 30, 2025 at 12:53 AM
And the fun part is it beacons out to the C2 to let the operator know the device is ready for compromise.
January 20, 2025 at 3:53 PM
This backdoor has the ability to execute remote commands and to take screen captures. It also self signs and attempts to hide its true name from inspection through osascript and System Events.
January 20, 2025 at 3:53 PM
That's going to result in a request to install Xcode's (current) command line tools if not already installed.
January 20, 2025 at 3:53 PM
This #macOS backdoor uses /usr/bin/SetFile to hide itself in the Finder. SetFile was deprecated in Xcode 6 (that's 2014 to humans)...not sure why it makes sense to declare smth 'deprecated' then leave it in the OS for 10+ years. 🤷‍♂️ #apple #malware
SHA1: 609088c54b99432aab212f35cfe74030b52f0320
January 20, 2025 at 3:53 PM
Thanks. 🫠
#macOS #dev
November 29, 2024 at 2:02 PM
The good old days, when you could open up a #Mac and play with the insides. 😀 #fixit #upgrade #repairability
That old 2009 MBP is still running today, too. 💜
November 29, 2024 at 1:44 PM
“It’s OK to eat [your enemy] because they don’t have any feelings”.
November 26, 2024 at 2:37 AM