Looks like DNS is not resolving. If this was ransomware then someone architected their whole network wrong. In what planet do you you have the same intranet/auth for external dns that is the same as your public dns in 2023??
It could be intentional because the systems are too compromised, and they had to just shut it all down. Where DNS is the safest and best place to enact a kill switch.