I honestly don’t know what method of any AV scanning https connection employs, as simply scanning the raw encrypted data is pretty much useless.

Encrypt a malware file that could be detected before encryption and scan it after encryption and it won’t be detected as the signature would be completely different.