That doesn't surprise me in the slightest. They could equally, put one of those control IRC servers that just happens to be on port 443 (it might use SSL too).
Firewalls, even content-filtering ones, typically just let anything through on HTTPS, because of course, as it's encrypted they can't tell what it is.
Some nasty-ware is bound to exploit this, and just make outgoing connections via HTTPS (or protocols indistinguishable from HTTPS)
Yes - either you ban HTTPS, or only allow it to given IP addresses - but that's not very good, as banks etc, change their IP addresses of their HTTPS servers from time to time (and/or use round-robin).
