I don't think it uses md5 any more, the newer protocol versions support sha256 hashes and thats only if the user checks, may not be what is used internally.
https://docs.aws.amazon.com/AmazonS3/latest/API/API_PutObjec...
For the object upload, AWSv4 request signature uses SHA256 on the payload/object, but I don't know if S3 also computes & compares the digest or just uses the x-amz-content-sha256 header value.
FYI S3 Object Lock requires Content-MD5 header.