If you find the right formula can you post the results for each address so we know exactly what ranges we can count with?
So far there is nothing to indicate that there is a "right formula" to predict the next private key given all the found private keys.
I believe the underlying sequence of private keys before masking to produce the shortened values was probably a secure RNG.