The firewall will do a route lookup in the VR that the ingress interface is in. In this case, it would be the VR that the Untrust zone is in, which by default is the trust-vr.
You have a few options.
1. Move the untrust zone to the untrust-vr
2. Add a route in the trust VR to point the traffic to the untrust-vr.