The point is that you isolate the VM after you get the file onto it but before running the potential malware. It's not going to auto-execute, not if your Windows is patched and modern and up to date, we don't live in the bad old days of floppy disks and CDs and USBs autorunning anymore (and for good reason).
If you are running a version of Windows (or anything) that is even capable of auto-executing code as it downloads, the malware you're trying to test is the least of your worries because you'll already have about a thousand other malware already running.