I suspect Cloudflare is doing some form of 'fingerprinting' to flag potential attacks. Fingerprinting is probably based on things like IP, user agent, js being enabled, etc.
In this case it seems that Cloudflare only banned a specific user agent with js_enabled=no.
Obviously this is all just an educated guess, since I've worked on building scrapers for cloudflare-protected websites.