I've been using LS for some time now and it's still pretty danged informative/maddening/overwhelming...
A tip: enable the Network Monitor, and you'll see a list of active and past network connections with a URL-type address to the right of the process name. Pick a random process then click on that URL-type address to the right of the process, and the Monitor will offer a drop-down menu with other hostnames with the same IP address - with some processes you could see quite a number of related hostnames. There's also a search field (which might take some time to filter), if you opt to search for something specifically.
The phobos-related processes I've seen are related to iTS and MAS connections.