Below is the update from Threatpulse. it appears to be an issue with the primary authoritative DNS provider that the domain uses.
A New Technical Case Comment has been added to: 5-081200008 by Russ Johnson
Case Comment: Matt,
This is what our NOC found:
The problem seems to be that the names for the authoritative domain servers (ns1.mountainthailand.com/ns2.mountainthailand.com) are not resolving. This is causing the site (www.aic.or.th) to fail DNS queries. Here is an example of the error when I query Google's DNS servers:
C02N528RG3QN:~/Documents/builds> dig @8.8.8.8 +trace www.aic.or.th
; DiG 9.8.3-P1 @8.8.8.8 +trace www.aic.or.th
; (1 server found)
;; global options: +cmd
. 19890 IN NS a.root-servers.net.
. 19890 IN NS b.root-servers.net.
. 19890 IN NS c.root-servers.net.
. 19890 IN NS d.root-servers.net.
. 19890 IN NS e.root-servers.net.
. 19890 IN NS f.root-servers.net.
. 19890 IN NS g.root-servers.net.
. 19890 IN NS h.root-servers.net.
. 19890 IN NS i.root-servers.net.
. 19890 IN NS j.root-servers.net.
. 19890 IN NS k.root-servers.net.
. 19890 IN NS l.root-servers.net.
. 19890 IN NS m.root-servers.net.
;; Received 228 bytes from 8.8.8.8#53(8.8.8.8) in 32 ms
th. 172800 IN NS dns1.thnic.co.th.
th. 172800 IN NS ams.sns-pb.isc.org.
th. 172800 IN NS ns-e.thnic.co.th.
th. 172800 IN NS ns.thnic.net.
th. 172800 IN NS sfba.sns-pb.isc.org.
th. 172800 IN NS ns-a.thnic.co.th.
th. 172800 IN NS th.cctld.authdns.ripe.net.
;; Received 462 bytes from 192.112.36.4#53(192.112.36.4) in 82 ms
aic.or.th. 7200 IN NS ns1.mountainthailand.com.
aic.or.th. 7200 IN NS ns2.mountainthailand.com.
dig: couldn't get address for 'ns1.mountainthailand.com': no more
Google's cache for the DNS entry has expired so they will not give an answer:
C02N528RG3QN:~/Documents/builds> host www.aic.or.th 8.8.8.8
Using domain server:
Name: 8.8.8.8
Address: 8.8.8.8#53
Aliases:
Host www.aic.or.th not found: 3(NXDOMAIN)
When I query OpenDNS's nameservers they give the same dig +trace result, but their cache probably hasn't expired yet so they give a response.
If the issue with ns1/ns2.mountainthailand.com is not resolved soon the site (www.aic.or.th) will become inaccessible everywhere as the cache TTL expires.