1. The target hash is 5f4dcc3b5aa765d61d8327deb882cf99. The in-page cracker hashes each wordlist entry (MD5) and compares. Why: MD5 is fast and unsalted, so a dictionary of candidates can be hashed and matched instantly.
2. The match is the word password. The flag is THM{cracked_md5_password}.
3. Enter the cracked word in the box to reveal/confirm the flag.
Lesson: store passwords with a unique salt and a slow KDF (bcrypt/argon2).