I figured out the problem.
Writing it here for future reference. The IP it was looking for is indeed an AWS IP address. It is the endpoint IP for AWS Directory service (ds.ap-southeast-1.amazonaws.com). Since DS do not have a VPC endpoint as of now, it is not possible to join the instances without internet access to the domain automatically.
Windows Ec2 instance seamless domain joinasked 2 months ago
AWS Managed MS AD DNS forwarder to ec2 domain instanceasked 2 years ago
How do I join a MS AD domain and still use SSM in a Private Subnet?asked 2 years ago
Allow Lambda to Access AWS Services+VPC+Internetasked 3 months ago
EC2 instance not able to join to AWS managed MS AD domainasked 3 years ago
How to get EC2 instance to access internet facing Network Loadbalancer.asked a year ago
joining an ec2 instance to a customers network/domainasked 5 months ago
Joining an AWS Managed Microsoft AD to an existing domainAccepted Answerasked 2 years ago
EC2 instance doesn't have access to internetasked 3 years ago
Accessing AWS FSX from a windows EC2 that is not joined to the same domain.asked 3 months ago