The answer to this question is obvious and the question doesn’t have to be asked. In what kind of thinking a product considered malware would imply that its generic components are also malware? It is clear logic fallacy. Same with C&C software - I don’t get how do you generalize it to IRC. I do not also see how this generalization can happen in law enforcement or courts.
1) this is on a spectrum. For libssl it's pretty obvious. For DHT? Significantly less obvious, I would say.
IRC gets a mention because it has been used as C&C for a VERY long time, and hasn't changed anything to prevent this from happening.
2) it's not experienced techies that will make this choice. It's uninformed judges or even police officers directly.
2) it is very unlikely that police will go after such software. They need to connect it to their case first and that requires technical expertise, so it will likely be a cybercrime unit.