Create a new rule before rule 1 which matches 1.1.1.1/32 and does not have a NAT action.
Something like this:
edit security nat source rule-set trust-to-untrust
rename rule 1 to rule 2
set rule 1 match source-address 10.0.0.0/8
set rule 1 match destination-address 1.1.1.1/32
set rule 1 then source-nat off
insert rule 1 before rule 2