You basically just run btcrecover with the --data-extract option instead of the --wallet option and specify all the other options (tokenlist, typos etc)... refer: https://btcrecover.readthedocs.io/en/latest/TUTORIAL/ for instructions on the various options you can use for trying to bruteforce the password... when prompted, input the second password "hash" that was extracted and the script will then attempt to bruteforce the password.