A lot of folks are suggesting it was a typo, and they intended to use bogus.apple.com instead, which is very very likely.
I can tell you with 100% certainty that standard HTTP request information is being sent to the domain. So, IPs for the connection, User Agents of the software used to connect, and the request URL. That's pretty much it in a nutshell.
I've seen a few iTunes UAs, both Windows and Mac, and since this news has made the rounds, the signal to noise ratio just went wayyyyyy down. (Go figure.)