x.co is a domain shortener. It was probably directing to a honeypot attempting to log people accessing that URL. Remember, these are payments sent
to the extortioner's address.
I think the search warrant that states really ignorant stuff like they are kicking in the door looking for pastebins shows it is just as likely he was operating a TOR exit node and somebody government crank got his IP address instead of realizing that they will not find the anonymous perpetrator.