The string in the description leads to a pastebin leak with a bunch of md5-hashed passwords. The only password that decrypts on the leak was 'pa$$2019' which is then used to open the attached keepass database. In there, there is a URL that points to the flag.
Flag: {n3v3r_r3cycl3_y0ur_53cr37_p455w0rd5}