When clicked with an android device it will redirect and download the "Android Security Update". Of-course never install anything that downloads seemingly out of no where and especially from a link in an email.
However, with the guises of an official security update and lack of permissions (The only permission it requires is use of the internet) a user may be tricked into installing this.
Info for the sites this redirects to can be found on Virus Total's reverse IP lookup feature using the IPs:
Once installed it runs in the background with no icon. It also takes up very little processing power and battery. How this app works is anytime the Android device connects to the internet the app will then announce itself to the Command and Control server and allow the device to be used as a TCP relay. The Android device can then be used as a Proxy to hide more criminal activity. It can potentially cause problems with devices on limited data plans or be used to steal unencrypted internet traffic through the device.
The current C&C server in this variation is:hxxp://45362545233224[dot]ru/
Originally it used hxxp://notcompatible[dot]eu/, hence the name NotCompatible.
Stay safe out there