Trojanized Android apps were uploaded to the Android Market using the same exploits detected by Kaspersky as ExploitAndroidOS.g and Exploit.AndroidOSLotoor.j. The Trojan seems to have been designed to collect IMEI and IMSI codes, together with specific device information. The stolen data is transferred to the cybercriminals server via a POST method through the HTTP protocol. At the time of writing, the malicious server is no longer accessible. It is possible that this 502 could be some kind of affiliate or partner ID.”]
Source: https://securelist.com/malware-in-the-android-market-part-2/29836/