Since these links are all relative, the browser uses the value from your [[++site_url]] tag in the base META tag. The site_url is generated on page load by the config.inc.php file - it is generated from several values taken from the reported SERVER values. For example, to determine it it's an HTTPS request
$isSecureRequest = ((isset ($_SERVER['HTTPS']) && strtolower($_SERVER['HTTPS']) == 'on') || $_SERVER['SERVER_PORT'] == $https_port);
And to get the host:
$http_host= array_key_exists('HTTP_HOST', $_SERVER) ? $_SERVER['HTTP_HOST'] : 'localhost';
So for some reason the server hiccups and reports itself as being the IP address, and reports HTTPS as being 'on'.
Do you recall if you had done something in the host's secure area immediately before loading the page in question? Could it be a cookie holdover from such a secure page request causing the server to still report itself as being on HTTPS?