Of course they did. When you paid with your card they knew your identity. Unless you were carding which is a pretty serious crime.
Who's the "they" in that sentence? As it stands, a certificate reseller knows that the Paypal account "some.name.here@gmail.com" paid for a SSL certificate for "www.unrelatedcompany.TLD"
The certificate itself tells you nothing about who paid for it - it doesn't even tell you which email account was used to confirm some level of association with the unrelatedcompany.TLD domain.
Q2: Can't the bad guys just buy a pre-paid debit card with cash if they're that desperate to cover their tracks?